Compromised package incidents
2390 confirmed incidents involving the compromised-package technique.
- activecritical
Malware in litespeed-cache
Malware discovered in the npm package litespeed-cache. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.
npmCompromised package - containedcritical
Malware in n8n-nodes-trust-me-im-totally-safe
Malware was discovered in the npm package n8n-nodes-trust-me-im-totally-safe, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malicious code in test2221 (npm)
The npm package test2221 version 2.2.4 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.
npmCompromised package - activecritical
Malware in @ai-plus/de-agent
The npm package @ai-plus/de-agent contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmAI agents & skillsCompromised package - activecritical
Malware in @ai-plus/de-agent-sdk
Malware discovered in the npm package @ai-plus/de-agent-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.
npmAI agents & skillsCompromised package - containedcritical
Malware in feedback-ai-sdk
Malware was discovered in the npm package feedback-ai-sdk. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in @zannstore/baileys
Malware was discovered in the npm package @zannstore/baileys. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.
npmCompromised package - containedcritical
Malware in stake-math
The npm package stake-math was found to contain malware. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.
npmCompromised package - containedcritical
Malware in data-parser-utils
Malware was discovered in the npm package data-parser-utils. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in @peptide-unit/peptide-modify
Malware discovered in the npm package @peptide-unit/peptide-modify. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in flight-compare-analyzer
Malware was discovered in the npm package flight-compare-analyzer. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in def-open-client
The npm package def-open-client contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in uniapi-bridge
Malware was discovered in the npm package uniapi-bridge, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.
npmCompromised package - containedcritical
Malware in aone-cloud-cli
Malware was discovered in the npm package aone-cloud-cli, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in ts-precision
Malware was discovered in the npm package ts-precision, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in lwp-web-client
The npm package lwp-web-client was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in @ai-agent-node/agent-node
Malware discovered in the npm package @ai-agent-node/agent-node. Systems with this package installed are considered fully compromised and require immediate remediation.
npmAI agents & skillsCompromised package - activecritical
Malware in @ai-agent-node/nodesql
The npm package @ai-agent-node/nodesql contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmAI agents & skillsCompromised package - activecritical
Malware in @ai-agent-node/createnode
Malware discovered in the npm package @ai-agent-node/createnode. Systems with this package installed are considered fully compromised and require immediate remediation.
npmAI agents & skillsCompromised package - resolvedcritical
Malware in colder-cli
The npm package colder-cli contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in lzd-unified-station-sdk
Malware discovered in the npm package lzd-unified-station-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in test-skill-zip
Malware was discovered in the npm package test-skill-zip. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in @peptide-unit/js-unimode
Malware discovered in the npm package @peptide-unit/js-unimode. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in poly-kelly
Malware was discovered in the npm package poly-kelly. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.
npmCompromised package - containedcritical
Malware in eslintcmd
The npm package eslintcmd was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-73c6-pgjj-9v82 was published on 2026-07-29.
npmCompromised package - containedcritical
Malware in ts-bn-proto
Malware was discovered in the npm package ts-bn-proto. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - containedcritical
Malware in @bowozzz/baileys
The npm package @bowozzz/baileys contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in polymarket-risk-manager
Malware was discovered in the npm package polymarket-risk-manager, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malicious code in @finxsecdemo/utils (npm)
The npm package @finxsecdemo/utils version 1.0.2 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.
npmCompromised package - containedcritical
Malware in zer0code
The npm package zer0code was found to contain malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in @omniwatch-wick/cli
Malware discovered in the npm package @omniwatch-wick/cli. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in chain-manager
Malware discovered in the npm package chain-manager. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in chain-analyze
Malware discovered in the npm package chain-analyze. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malicious code in @mypwn/hawkeye (npm)
The npm package @mypwn/hawkeye version 99.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.
npmCompromised package - containedcritical
Malicious code in blots (npm)
The npm package 'blots' version 2.1.0 was identified by the OpenSSF Package Analysis project as containing malicious code that executes commands associated with malicious behavior. The package has been flagged in the OpenSSF malicious packages database.
npmCompromised package - containedcritical
Malicious code in toll_free (npm)
The npm package toll_free version 1.0.1 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.
npmCompromised package - containedcritical
Malware in open-worker-cli
Malware was discovered in the npm package open-worker-cli. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malicious code in num-format-helper (npm)
The npm package num-format-helper version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.
npmCompromised package - resolvedcritical
Malicious code in bianira-ui (npm)
The npm package bianira-ui contained malicious code that executed on import, enabling remote code execution via a blockchain-based dead-drop C2 mechanism. The payload used unicode escapes to evade detection and dynamically resolved C2 endpoints through Ethereum transactions.
npmCompromised package - resolvedcritical
Malicious code in cfgzen (PyPI)
Malicious code was discovered in the cfgzen PyPI package, embedded in a native module that functions as an infostealer. The malicious code downloads and executes an encrypted remote executable, with capabilities to exfiltrate environment variables and detect sandbox environments. The package has been identified as part of campaign 2026-07-cfgzen.
2026 07 CfgzenPyPICompromised package - activecritical
Malware in @vaultflow/create-flow
Malware discovered in the npm package @vaultflow/create-flow. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @joyfill/components
Malware was discovered in the npm package @joyfill/components. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in @joyfill/layouts
Malware was discovered in the npm package @joyfill/layouts. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malicious code in @apexfnd/apex (npm)
The npm package @apexfnd/apex contained a malicious postinstall script that executed remote code at install time. On macOS, it prompted for administrator credentials and executed a shell script as root; on all platforms, it downloaded and executed an unsigned binary from attacker-controlled infrastructure.
npmCompromised package - containedcritical
Malicious code in @crbrc/xbt (npm)
The npm package @crbrc/xbt contains malicious code that exfiltrates OxaPay payment-gateway secrets and host metadata to a hardcoded attacker-controlled IP address, establishes a reverse TCP proxy tunnel, and allows remote process termination. The malicious behavior is conditionally activated only when all project source files import the companion package @crb/xbr.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in ethers-secure (npm)
The npm package ethers-secure, which mimics the popular ethers library, contained malicious code that exfiltrated Ethereum private keys to an attacker-controlled server (enjbyg3xk8l.x.pipedream.net) whenever its wallet API was used. The package was identified by Amazon Inspector and credited to the OpenSSF malicious-packages project.
npmCompromised packageTyposquatting - containedcritical
Malicious code in api-rust-sdk (npm)
The npm package api-rust-sdk contained malicious code in its postinstall hook that harvested credentials (Solana keypairs, Rust configs, dotenv secrets), exfiltrated files matching attacker-defined patterns, and installed a persistent SSH backdoor on infected systems.
npmCompromised package - containedcritical
Malicious code in color-convert-helper (npm)
The npm package color-convert-helper contained malicious code in its postinstall.js script that harvested cloud credentials, IAM tokens, and environment variables from infected systems, then exfiltrated the data to an attacker-controlled OAST domain. The package also performed internal network reconnaissance.
npmCompromised package - resolvedcritical
Malicious code in react-puller (npm)
The npm package react-puller contained malicious code in its postinstall hook that downloads and executes Windows binaries from a hardcoded IP endpoint, establishing persistence via Windows registry autostart.
npmCompromised package - containedcritical
Malicious code in api-node-sdk (npm)
The npm package api-node-sdk contained malicious code in its postinstall hook that harvested secrets, established persistent SSH access, and exfiltrated files from infected systems. The package executed attacker-controlled workflows to scan for and steal configuration files, keypairs, and environment variables, then installed SSH backdoors and enabled remote access.
npmCompromised package - resolvedcritical
Malicious code in tidal-embed-player (npm)
The npm package tidal-embed-player contained malicious code that executed on installation, collecting host identifiers and system files, then exfiltrating the data to an attacker-controlled domain. The package had no legitimate functionality despite its name suggesting a Tidal media player.
npmCompromised package - resolvedcritical
Malicious code in streak-core-math (npm)
The npm package streak-core-math contained malicious code that downloads and executes a binary on Windows developer machines. The payload fetches a ZIP file from Backblaze B2, unpacks it, and establishes persistence via a VBS launcher in the Windows Startup folder.
npmCompromised package - containedcritical
Malicious code in karpatkey (PyPI)
The karpatkey package on PyPI contained malicious code that exfiltrated sensitive credentials and data from infected systems. Upon import, the package spawned a background daemon thread that collected SSH keys, AWS/GCP credentials, kubeconfig, cryptocurrency wallets, and other secrets, then transmitted them via HTTP to hardcoded IP addresses.
PyPICompromised packageMalicious commit - containedcritical
Malicious code in mrmustard (PyPI)
A malicious version of the mrmustard package was published to PyPI containing code that exfiltrates SSH keys, AWS credentials, Kubernetes config, environment variables, and system identifiers to a remote endpoint. The payload includes multiple persistence mechanisms that survive package uninstallation.
PyPICompromised package - containedcritical
Malicious code in karpatkit (PyPI)
The karpatkit package on PyPI contained malicious code that exfiltrated sensitive credentials and secrets on import. The package spawned a daemon thread collecting environment variables, cloud credentials, SSH keys, Kubernetes tokens, cryptocurrency wallets, and shell histories, then transmitted them via HTTP to hardcoded IP addresses.
PyPICompromised packageMalicious commit - resolvedcritical
Malicious code in xerohub-discord-voice-v3 (npm)
The npm package xerohub-discord-voice-v3 contained malicious code that exfiltrated Discord user authentication tokens to a hardcoded webhook URL controlled by the package author. The startVoiceJoiner() function unconditionally sent raw tokens, usernames, guild IDs, and voice channel IDs to discord.com/api/webhooks/1528726419046404196 before executing any legitimate voice functionality.
npmCompromised packageMalicious maintainer - containedcritical
Malicious code in @ai_/autoprefixers (npm)
@ai_/autoprefixers is a typosquat of the legitimate autoprefixer package that executes arbitrary attacker-controlled shell commands on installation. The malicious code fetches encrypted payloads from remote C2 servers and decrypts them using a hardcoded key suffix before execution via child_process.exec.
npmTyposquattingCompromised package - containedcritical
Malicious code in app-soda-layer (npm)
The npm package app-soda-layer contained malicious code in its postinstall hook that exfiltrated sensitive files, enumerated the filesystem, and injected SSH keys for persistent remote access. The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.
npmCompromised package - containedcritical
Malicious code in dev-helper-bg (PyPI)
The PyPI package dev-helper-bg contained malicious code that executed arbitrary commands on import. The package decrypted and executed remotely-controlled code fetched from an external endpoint, and spawned a Telegram bot for command and control.
2026 07 Make HelperPyPICompromised packageMalicious commit - resolvedcritical
Malicious code in kordyn (npm)
The npm package kordyn contained malicious code: a base64-encoded Windows PE64 executable embedded in its main entry point (index.mjs). When imported in a Linux WSL environment, the module writes the binary to the Windows Startup folder, achieving persistence and code execution on the developer's Windows host.
npmCompromised package - containedcritical
Malicious code in app-sima-layer (npm)
The npm package app-sima-layer contained malicious code in its postinstall script that performed coordinated attacks: installing SSH backdoors on Linux, stealing wallet and configuration files, and harvesting files matching attacker-controlled patterns from the host system.
npmCompromised package - resolvedcritical
Malicious code in app-sim-layer (npm)
The npm package app-sim-layer contained malicious code in a postinstall hook that exfiltrated sensitive files (Solana keypairs, API keys, credentials), enumerated the user's filesystem, and on Linux granted remote SSH access to attacker infrastructure at 95.216.118.146.
npmCompromised packageMalicious commit - containedcritical
Malicious code in @yancyyu/agentcli (npm)
The npm package @yancyyu/agentcli contains malicious code that extracts OAuth credentials and API keys for Lark/Feishu from the system keychain (macOS) and credential store (Windows), then exfiltrates them to a hardcoded remote IP address over plaintext HTTP. A persistent launchd agent ensures the exfiltration loop survives reboots.
npmAI agents & skillsCompromised packageMalicious commit - containedcritical
Malicious code in chain-analyze (npm)
The npm package chain-analyze contained malicious code that executed arbitrary Node.js commands on installation. The package impersonated the official Theta blockchain SDK and used a split-package design with a dependency (chain-manager) to hide encrypted payload from scanners.
npmCompromised packageTyposquatting - resolvedcritical
Malicious code in node-array-plus (npm)
node-array-plus, an npm package with no legitimate functionality, contained heavily obfuscated malicious code that downloads, decrypts, and executes remote code on installation. The package was identified and reported by OpenSSF's malicious-packages project.
npmCompromised package - resolvedcritical
Malicious code in fluid-type-ui (npm)
fluid-type-ui@2.0.8 on npm contains hidden malicious code that executes arbitrary attacker-controlled code on module load via an Ethereum-based command-and-control mechanism. The code queries Ethereum JSON-RPC endpoints for instructions embedded in blockchain transactions, making it resistant to traditional takedown.
npmCompromised package - containedcritical
Malicious code in json-schema-inspector (npm)
The npm package json-schema-inspector contained malicious code that performed remote code execution on installation. The package advertised itself as a JSON/XML schema validator but included a trigger routine that fetched and executed attacker-controlled payloads from a remote manifest.
npmCompromised packageMalicious commit - containedcritical
Malicious code in parallely (npm)
The npm package parallely contains malicious code that impersonates the legitimate concurrently package. When invoked, it executes a dropper that downloads and runs platform-specific payloads after anti-analysis checks.
npmCompromised packageTyposquatting - containedcritical
Malicious code in app-svm-layer (npm)
The npm package app-svm-layer contained malicious code in its postinstall script that executed automatically on install, establishing unauthorized SSH access, exfiltrating credentials and configuration files, and scanning for sensitive data across the host system.
npmCompromised package - resolvedcritical
Malicious code in basic-vite (npm)
The npm package basic-vite contained malicious code that executed automatically during installation, collecting and exfiltrating sensitive host identity data and system files to an attacker-controlled server.
npmCompromised package - resolvedcritical
Malicious code in jobber-app-template-react (npm)
The npm package jobber-app-template-react contained malicious code in its preinstall hook that executed automatically on npm install. The script performed host reconnaissance and exfiltrated sensitive system information to a Burp Collaborator domain.
npmCompromised package - resolvedcritical
Malicious code in array-node-utils (npm)
The npm package array-node-utils contained malicious code that fetches, decrypts, and executes arbitrary code on installation. The package's declared purpose (array utilities) bore no relationship to the shipped obfuscated payload.
npmCompromised package - containedcritical
Malicious code in streak-core-lib (npm)
streak-core-lib@1.0.0 on npm contains malicious code that drops a Windows PE executable to the Startup folder on installation, achieving persistent code execution. The package falsely advertises itself as a day-math primitives library and executes the payload automatically on import without user interaction.
npmCompromised package - resolvedcritical
Malicious code in triage_bot_using_sdkv3 (npm)
The npm package triage_bot_using_sdkv3 contained malicious code that executed during installation, exfiltrating system information and local files to an attacker-controlled endpoint. The package registered a preinstall hook that collected hostname, user information, DNS configuration, and sensitive files like /etc/passwd and /etc/hosts.
npmCompromised package - resolvedcritical
Malicious code in xerohub-discord-voice-v2 (npm)
The npm package xerohub-discord-voice-v2 contained malicious code that silently exfiltrated Discord user tokens and server/channel IDs to an attacker-controlled webhook URL when users invoked the advertised `startVoiceJoiner(config)` API with their credentials.
npmCompromised package - containedcritical
Malicious code in text-line-parser (npm)
The npm package text-line-parser contained malicious code in its postinstall.js that collected system information, environment variables (including CI tokens and cloud credentials), and exfiltrated them to a Burp Collaborator domain. The package advertised itself as a text-parsing utility but shipped only stub functions, consistent with a typosquat/decoy supply-chain attack.
npmCompromised packageTyposquatting - resolvedcritical
Malicious code in rollup-runtime-core-polyfills (npm)
The npm package rollup-runtime-core-polyfills contained malicious code that impersonated a legitimate rollup polyfill plugin. On every import/require, it decoded and executed a shell command to install an attacker-controlled package (svgcraft-core) and executed code from it, affecting any build system that consumed this package.
npmCompromised packageTyposquatting - containedcritical
Malicious code in streak-daily-lib (npm)
The npm package streak-daily-lib contained malicious code that executes on import, downloads and executes binaries from attacker-controlled infrastructure, and establishes persistence on Windows hosts via WSL. The package was published with a benign stated purpose (calendar/streak math) but implements a sophisticated supply chain attack with cross-platform capabilities.
npmCompromised package - containedcritical
Malicious code in sigchain-js (npm)
Malicious code was injected into the published npm package sigchain-js, executing arbitrary code on installation via DES-decrypted payloads from companion packages thedata and tchain-api. The attack also involved typosquatting axios to version 1.18.1, which does not exist in legitimate release history.
npmCompromised packageDependency confusionTyposquatting - containedcritical
Malicious code in simple-probe-utils (npm)
The npm package simple-probe-utils contained malicious postinstall code that harvested cloud provider credentials (AWS IAM, Tencent, Aliyun, GCP, Azure) and exfiltrated them to an attacker-controlled domain. The package was masqueraded as a string formatting utility but contained only credential-stealing functionality.
npmCompromised package - containedcritical
Malicious code in govapkg (PyPI)
govapkg, a malicious PyPI package, downloads and executes a hidden binary on first use, establishing persistence via a systemd desktop autostart entry. The package obfuscates its malicious behavior through base64-encoded URLs and downloads from unverified external sources.
PyPICompromised packageMalicious commit - resolvedcritical
Malicious code in vtranalytic (PyPI)
The vtranalytic package on PyPI contained malicious code implementing a Telegram-bot-driven remote administration tool that provides full system control to an attacker holding the configured bot token. The package exfiltrates credentials, SSH keys, and arbitrary files via Telegram API, and executes arbitrary shell commands through a documented `run` command.
PyPICompromised packageMalicious maintainer - containedcritical
Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan
Malicious beta versions of npm packages @joyfill/components and @joyfill/layouts were published containing an obfuscated remote access trojan and credential stealer. The compromise affected developers who installed these packages during the malicious release window.
npmCompromised package - containedcritical
Malware in postcss-motion-utils
Malware was discovered in the npm package postcss-motion-utils. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in cloud-config-fetcher
Malware was discovered in the npm package cloud-config-fetcher. Any system with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in aone-kit
The npm package aone-kit contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in local-config-parser
Malware was discovered in the npm package local-config-parser. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in smart-config-manager
Malware was discovered in the npm package smart-config-manager. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.
npmCompromised package - containedcritical
Malware in aone-kit-cli
Malware was discovered in the npm package aone-kit-cli, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in aone-sandbox
The npm package aone-sandbox contained malware that compromised any system where it was installed or executed. The package granted outside entities full control of affected computers.
npmCompromised package - containedcritical
Malware in lib-mtop
Malware was discovered in the npm package lib-mtop, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malicious code in json-to-table-util (npm)
The npm package json-to-table-util version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.
npmCompromised package - containedcritical
Malicious code in string-format-kit (npm)
The npm package string-format-kit version 1.0.2 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.
npmCompromised package - containedcritical
Malicious code in date-sanitize-helper (npm)
The npm package 'date-sanitize-helper' version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity and executes commands associated with malicious behavior.
npmCompromised package - activecritical
Malware in @vaultflow/update-flow
Malware was discovered in the npm package @vaultflow/update-flow. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - resolvedcritical
Malicious code in korvica (npm)
The npm package korvica contained malicious code that, on import in non-production Linux/WSL environments, fetches and executes an unsigned binary to the Windows Startup folder. The payload is obfuscated using single-letter variables and template literals to evade detection.
npmCompromised package - containedcritical
Malicious code in lib-streak-math (npm)
The npm package lib-streak-math contained obfuscated malicious code that executes on import, downloading and executing a remote payload. On Windows, it establishes persistence via startup folder; on Linux, it spawns a detached background service.
npmCompromised package - containedcritical
Malicious code in array-sort-helper (npm)
The npm package array-sort-helper version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.
npmCompromised package - containedcritical
Malicious code in @antv/gi-assets-galaxybase (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-galaxybase, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.
Mini Shai HuludnpmAccount takeoverCompromised package - resolvedcritical
Malicious code in truffle-js (npm)
The npm package truffle-js (version 2.0.0) contained malicious code that executed arbitrary remote content via curl during installation. The package name resembles the legitimate 'truffle' Ethereum toolkit, consistent with a typosquatting attack.
npmCompromised packageTyposquatting - containedcritical
Malicious code in amapcn (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including amapcn, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - activecritical
Malware in motion-forge-css
The npm package motion-forge-css contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malicious code in ethers-common (npm)
The npm package ethers-common v1.0.0 contained malicious code that executed arbitrary commands during installation via a postinstall hook. The package impersonated the legitimate ethers Web3 library and used a base64-obfuscated URL to fetch and execute attacker-controlled code over plain HTTP.
npmCompromised packageTyposquatting - resolvedcritical
Malicious code in cdp-core (npm)
The npm package cdp-core contained malicious code (cdp_inject.js) designed to harvest system information and credentials, then exfiltrate them over HTTPS to a hardcoded remote server. The package provided no legitimate functionality and was identified by OpenSSF's malicious-packages project.
npmCompromised package - containedcritical
Malicious code in paysafe-gbp-virtual-assistant-lib-fe (npm)
The npm package paysafe-gbp-virtual-assistant-lib-fe version 2.0.4 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.
npmCompromised package - containedcritical
Malicious code in @antv/gi-assets-janusgraph (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-assets-janusgraph, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmCompromised packageAccount takeover - containedcritical
Malicious code in ethers-io (npm)
The npm package ethers-io (version 2.0.0) contained malicious code that executed arbitrary shell commands during installation via a postinstall script. The package impersonates the legitimate ethers.js ecosystem and fetches and executes attacker-controlled code from a bare IPv4 address over unencrypted HTTP.
npmCompromised packageTyposquatting - containedcritical
Malicious code in @antv/gi-cli (npm)
The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-cli, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/react-g (npm)
The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/react-g, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/l7-mini (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/l7-mini, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.
Mini Shai HuludTeamPCPnpmCompromised packageAccount takeover - containedcritical
Malicious code in @antv/xflow-diff (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/xflow-diff. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/gi-assets-tugraph-analytics (npm)
The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-tugraph-analytics, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.
Mini Shai HuludnpmAccount takeoverCompromised package - resolvedcritical
Malicious code in request-logger-canary (npm)
request-logger-canary@1.0.0 on npm contains a malicious preinstall.js script that establishes a reverse shell to 52.74.242.200:8851 when npm install runs, granting remote interactive shell access. The package README falsely claims the payload is dead code in postinstall.js, indicating deliberate obfuscation.
npmCompromised package - containedcritical
Malicious code in @antv/github-config-cli (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages in an automated attack. The @antv/github-config-cli package was modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/gi-theme-antd (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-theme-antd, each injecting a preinstall hook executing an obfuscated Bun script. The attack exfiltrated credentials via GitHub API and established persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/gi-assets-xlab (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-assets-xlab, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @tc-core/campus-service (npm)
The npm package @tc-core/campus-service version 0.0.0-defensive-callback was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.
npmCompromised package - containedcritical
Malicious code in @antv/l7-pass (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/l7-pass, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/x6-react (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/x6-react, each injecting a preinstall hook that executes an obfuscated Bun script to exfiltrate credentials via GitHub API. The attack also establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmCompromised packageAccount takeover - containedcritical
Malicious code in @antv/l7-three (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/l7-three, each injecting a preinstall hook that executes an obfuscated Bun script to exfiltrate credentials and establish persistence. The attack targeted AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, and Slack tokens.
Mini Shai HuludTeamPCPnpmCompromised packageAccount takeover - containedcritical
Malicious code in @antv/word-scale-chart (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/word-scale-chart, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmCompromised packageAccount takeover - containedcritical
Malicious code in vue-template-compiler-plugin (npm)
A malicious npm package named vue-template-compiler-plugin impersonates the legitimate vue-template-compiler library and contains a full C2 implant. The postinstall hook decodes and executes a remote-access trojan that registers victims to a Cloudflare tunnel C2 server and beacons for commands.
npmCompromised packageTyposquatting - containedcritical
Malicious code in chalk-pack (npm)
A malicious npm package named chalk-pack impersonated the legitimate chalk library and executed a two-stage stealer on install: harvesting npm credentials, environment variables, and cryptocurrency wallet data from browser extensions and local files, exfiltrating to a hardcoded C2 server.
npmCompromised packageTyposquatting - resolvedcritical
Malicious code in @webapp-next/store (npm)
The npm package @webapp-next/store contained malicious code that executed automatically on installation, collecting system and user information and exfiltrating it to an attacker-controlled server. The package had no legitimate functionality and used a dependency-confusion lure with a scope resembling a legitimate namespace.
npmCompromised packageDependency confusion - resolvedcritical
Malicious code in cache-poisoning-pwn-demo (npm)
The npm package cache-poisoning-pwn-demo contains malicious code in its postinstall hook and main entry point that executes platform-specific calculator commands at install-time and import-time without user consent. The package is self-described as a supply-chain attack demonstration, but the delivery mechanism is a fully functional arbitrary-command executor.
npmCompromised package - containedcritical
Malicious code in @design-system-coopeuch/web (npm)
@design-system-coopeuch/web versions 999.0.4 and 999.0.0 on npm contained malicious code implementing a dependency-confusion attack. The package included a preinstall hook that exfiltrated host identifiers (hostname, working directory, user ID, environment variables) to a hardcoded IP address via cleartext HTTP.
npmDependency confusionCompromised package - containedcritical
Malicious code in exxpress-tool (npm)
The npm package exxpress-tool (a one-character typosquat of express) contains malicious postinstall code that harvests npm tokens, git credentials, environment variables, and cryptocurrency wallet seeds from developer machines and CI environments, exfiltrating them to a hardcoded IP endpoint.
npmCompromised packageTyposquatting - containedcritical
Malicious code in glob-helper (npm)
glob-helper@1.0.2 is a malicious typosquat package that executes a postinstall script to steal npm tokens, AWS credentials, GitHub tokens, and cryptocurrency wallet data from developer machines. The stolen data is exfiltrated to a hardcoded C2 server at http://149.28.127.35:8888 over plain HTTP.
npmTyposquattingCompromised package - containedcritical
Malicious code in env-threads (npm)
The npm package env-threads is a typosquat of the legitimate dotenv package that executes arbitrary code hidden in a steganographic JPEG payload when required. The malicious package copies dotenv's README, repository URL, homepage, description, keywords, and API surface, but ships an 82 KB obfuscated main.js that decodes and executes the hidden payload via child_process at module load time.
npmTyposquattingCompromised package - containedcritical
Malicious code in nock-helper (npm)
The npm package nock-helper contained a malicious postinstall script that harvested credentials, API keys, and cryptocurrency wallet data from infected systems. The script exfiltrated npm tokens, environment variables, git credentials, and browser wallet extension data to a hardcoded C2 server.
npmCompromised packageMalicious commit - containedcritical
Malicious code in chalk-utils (npm)
The npm package chalk-utils contained malicious code in its postinstall.js script that steals credentials, cryptocurrency wallet data, and sensitive files from developer machines. The package masquerades as a chalk utility while executing a credential and cryptocurrency stealer on installation.
npmCompromised packageTyposquatting - containedcritical
Malicious code in joi-pack (npm)
The npm package joi-pack contained malicious code in a postinstall hook that harvested npm tokens, API keys, cloud credentials, and cryptocurrency wallet data from infected systems. The malicious script exfiltrated stolen credentials to a hardcoded C2 server at 149.28.127.35:8888.
npmCompromised package - containedcritical
Malicious code in rimraf-utils (npm)
rimraf-utils@1.0.5 on npm contains malicious code that impersonates the legitimate rimraf package. The postinstall script harvests sensitive credentials (npm tokens, API keys, crypto wallet seeds, private keys) and exfiltrates them to a hardcoded C2 server at 149.28.127.35:8888 over plaintext HTTP.
npmCompromised packageTyposquatting - containedcritical
Malicious code in truffle-helper (npm)
The npm package truffle-helper version 2.0.0 contains malicious code that executes arbitrary commands during installation via npm lifecycle scripts, fetching and executing remote content without user consent.
npmCompromised package - containedcritical
Malicious code in @antv/matrix-util (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/matrix-util, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/l7-extension-g-layer (npm)
A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in an automated 22-minute burst as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in bui-react-10components (npm)
The npm package bui-react-10components was found to contain malicious code that communicates with a domain associated with malicious activity. The malicious version 99.0.0 was identified by both Amazon Inspector and the OpenSSF Package Analysis project.
npmCompromised package - containedcritical
Malicious code in @antv/my-f2-pc (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/my-f2-pc, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/stat (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/stat, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure/Kubernetes credentials, SSH keys, Docker configs, database strings, Stripe/Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/narrative-text-editor (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/narrative-text-editor, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmCompromised packageAccount takeover - containedcritical
Malicious code in web3-core-js (npm)
The npm package web3-core-js (version 2.0.0) contained malicious code that executed arbitrary remote commands during installation. The package mimicked the legitimate web3/web3-core ecosystem but contained only a lifecycle hook that fetched and executed attacker-controlled code via curl.
npmCompromised packageTyposquatting - containedcritical
Malicious code in @datatrain/passenger-v3 (npm)
The npm package @datatrain/passenger-v3 version 99.99.99 was found to contain malicious code that communicates with attacker-controlled domains and executes malicious commands. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.
npmCompromised package - containedcritical
Malicious code in @antv/x6-angular-shape (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/x6-angular-shape, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmCompromised packageAccount takeover - containedcritical
Malicious code in boring-avatars-vanilla (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including boring-avatars-vanilla, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmCompromised packageAccount takeover - containedcritical
Malicious code in @antv/semantic-release-pnpm (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/semantic-release-pnpm, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/mcp-server-antv (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/mcp-server-antv, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/li-aiearth-assets (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/x6-vector (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/x6-vector, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/hierarchy (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/hierarchy, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in identitysecuretokenserv (npm)
The npm package identitysecuretokenserv version 10.0.0 was found to contain malicious code that communicates with domains associated with malicious activity and executes commands associated with malicious behavior. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.
npmCompromised package - containedcritical
Malicious code in @antv/g6-wx (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g6-wx, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.
Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/l7-map (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-map, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/xflow-core (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/xflow-core, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/webgpu-graph (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/webgpu-graph, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @citi-icg-158830/elemental-chameleon (npm)
The npm package @citi-icg-158830/elemental-chameleon version 0.0.0-defensive-callback.1 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.
npmCompromised package - containedcritical
Malicious code in @antv/scale (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/scale, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/gi-assets-neo4j (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-neo4j, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in apex-trading (npm)
The npm package apex-trading was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. Version 1.0.4 executes commands associated with malicious behavior.
npmCompromised package - containedcritical
Malicious code in mcp-echarts (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including mcp-echarts, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in dotenvv-tool (npm)
The npm package dotenvv-tool is a typosquatting attack impersonating the popular dotenv package. It contains a malicious postinstall script that harvests npm credentials, environment variables, git credentials, cryptocurrency wallet data, and system information, exfiltrating them to a hardcoded C2 server.
npmTyposquattingCompromised package - containedcritical
Malicious code in hello-world-pkg-value-value-p (npm)
The npm package hello-world-pkg-value-value-p contains malicious code in its postinstall hook that executes a reverse shell to attacker-controlled IP 52.249.218.132 on port 8080. Installation grants unauthenticated remote code execution to the attacker with the privileges of the installing user.
npmCompromised package - containedcritical
Malicious code in @wagni_bot/eth (npm)
A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/eth, were published on 2026-07-09 as crypto/web3 typosquats. Each package contained a postinstall hook that steals SSH keys, wallet files, .env secrets, and exfiltrates them to a hardcoded Telegram bot.
npmTyposquattingCompromised package - containedcritical
Malicious code in @wagni_bot/hyperliquid (npm)
A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/hyperliquid, deployed credential-stealing malware via postinstall hooks. Published 2026-07-09, the packages exfiltrated SSH keys, cryptocurrency wallets, and .env secrets to a single Telegram bot.
npmTyposquattingCompromised package - containedcritical
Malicious code in @wagni_bot/wagni (npm)
A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/wagni, were published on 2026-07-09 as typosquats. Each package contains a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, .env files, and system fingerprints to a hardcoded Telegram bot.
npmCompromised packageTyposquatting - containedcritical
Malicious code in @wagni_bot/polymarket (npm)
The npm package @wagni_bot/polymarket is a typosquatted credential stealer that is part of a coordinated campaign of 25 malicious packages published under the @wagni_bot scope on 2026-07-09. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, and .env files to a hardcoded Telegram bot.
npmTyposquattingCompromised package - containedcritical
Malicious code in @wagni_bot/bsc (npm)
A coordinated campaign of 25 typosquat npm packages under the @wagni_bot scope, including @wagni_bot/bsc, were published on 2026-07-09 as credential stealers. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, and .env secrets to a single Telegram bot.
npmTyposquattingCompromised package - containedcritical
Malicious code in @wagni_bot/polygon (npm)
The npm package @wagni_bot/polygon is a credential stealer disguised as a Polygon SDK, part of a coordinated 25-package typosquatting campaign published under @wagni_bot on 2026-07-09. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, .env files, and system fingerprints to a hardcoded Telegram bot.
npmTyposquattingCompromised package - containedcritical
Malicious code in @wagni_bot/metamask (npm)
The npm package @wagni_bot/metamask is a credential stealer disguised as a MetaMask SDK, part of a coordinated campaign of 25 typosquat packages published under @wagni_bot on 2026-07-09. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, and .env files to a hardcoded Telegram bot.
npmTyposquattingCompromised package - containedcritical
Malicious code in @wagni_bot/opensea (npm)
A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/opensea, were published on 2026-07-09 as typosquats of legitimate crypto/web3 libraries. Each package contained a postinstall hook that steals SSH keys, cryptocurrency wallets, .env files, and other secrets, exfiltrating them to a single Telegram bot.
npmTyposquattingCompromised package - containedcritical
Malicious code in @wagni_bot/web3 (npm)
The npm package @wagni_bot/web3 and 24 other packages under the @wagni_bot scope are typosquats that execute a postinstall hook to steal SSH keys, cryptocurrency wallets, .env files, and other secrets, exfiltrating them to a hardcoded Telegram bot. All 25 packages are part of a single coordinated campaign published on 2026-07-09.
npmTyposquattingCompromised package - activecritical
Malicious code in whiteboard-agent (npm)
The whiteboard-agent npm package contains malicious code in its postinstall script that silently exposes a local HTTP server to the public internet via Cloudflare tunnel in non-interactive environments (CI/CD, build agents), creates an unauthenticated admin account, and fetches an unsigned binary from a mutable release tag.
npmCompromised packageMalicious commit - containedcritical
Malicious code in supership-scan (npm)
The npm package supership-scan contains malicious code that exfiltrates source code and environment files (including .env files with secrets) to an attacker-controlled endpoint (https://supership.crestsystems.ai/scan/), despite marketing claims that code never leaves the machine. The package is particularly dangerous when used as an MCP server with AI coding agents.
npmCompromised packageMalicious commit - containedcritical
Malicious code in secdriven (npm)
The npm package 'secdriven' version 1.0.8 contains malicious postinstall code that exfiltrates host identity, username, working directory, and CI environment variables to a third-party OOB-detection endpoint. The package is a dependency-confusion payload targeting Google's internal namespace, masquerading as a security research canary.
npmDependency confusionCompromised package - containedcritical
Malicious code in seekcode (npm)
The seekcode npm package contains malicious code that redirects users selecting the deepseek-cn provider to a typosquatted domain (api.deepseeki.com instead of api.deepseek.com), exfiltrating API credentials and chat prompt contents to an attacker-controlled server.
npmCompromised packageTyposquatting - resolvedcritical
Malicious code in tempo-components (npm)
The npm package tempo-components contained malicious code (poc.js) that collected host metadata and identity information and exfiltrated it to an external endpoint. The package performed system reconnaissance by capturing hostname, platform, and user identity before transmitting the data via HTTPS.
npmCompromised package - resolvedcritical
Malicious code in wrld-dev (npm)
The npm package wrld-dev contained malicious code that silently relayed user authentication credentials (email and password) to an attacker-controlled Supabase tenant. The package also shipped hardcoded Supabase service_role JWT tokens that grant full database admin access to two Supabase projects.
npmCompromised package - activecritical
Malicious code in xy-ai-chat (npm)
The npm package xy-ai-chat contains a Lit web component that silently exfiltrates all end-user chat input to a hardcoded attacker-controlled server (182.43.87.39) over plain HTTP with no TLS or configurability. Any site embedding this component routes user data to the attacker without consent or visibility.
npmCompromised package - resolvedcritical
Malicious code in pretty-logger-utils (npm)
pretty-logger-utils is a malicious npm package that triggers malware behavior from a dependency (terminal-logger-utils) upon installation or import. The attack chain includes a postinstall hook that executes an obfuscated dropper, which downloads and runs a platform-specific second-stage binary from Hugging Face that provides keylogger, infostealer, and RAT capabilities.
npmCompromised package - containedcritical
Malicious code in vfat-tools (npm)
The npm package vfat-tools version 2.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.
npmCompromised package - containedcritical
Malicious code in sickle-wrapper (npm)
The npm package sickle-wrapper version 0.2.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.
npmCompromised package - containedcritical
Malicious code in paysafe-gbp-virtual-terminal-lib-fe (npm)
The npm package paysafe-gbp-virtual-terminal-lib-fe version 3.1.13 was found to contain malicious code that communicates with domains associated with malicious activity and executes commands associated with malicious behavior. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.
npmCompromised package - containedcritical
Malicious code in @antv/g-webgpu-raytracer (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-webgpu-raytracer, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.
Mini Shai HuludnpmCompromised packageAccount takeover - containedcritical
Malicious code in @antv/g6-element (npm)
The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g6-element. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure/Kubernetes credentials, SSH keys, Docker configs, database strings, Stripe/Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/gatsby-theme (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gatsby-theme. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - activecritical
Malicious code in @antv/gi-assets-hugegraph (npm)
The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-hugegraph. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/gi-assets-tugraph (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages in a 22-minute automated burst, part of the "Mini Shai-Hulud" supply chain attack campaign. @antv/gi-assets-tugraph was among the affected packages, modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/l7-mapkit (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-mapkit, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/s2-react-components (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/s2-react-components, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/x6-components (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/x6-components, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in apex-connector (npm)
The npm package apex-connector version 1.0.4 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.
npmCompromised package - containedcritical
Malicious code in claude-code-base-action (npm)
The npm package claude-code-base-action v2.0.0 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.
npmCompromised package - containedcritical
Malicious code in @antv/g6-alipay (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g6-alipay, in a coordinated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.
Mini Shai HuludnpmCompromised packageAccount takeover - containedcritical
Malicious code in @antv/g6-cli (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-cli, in an automated 22-minute burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure/Kubernetes credentials, SSH keys, Docker configs, database strings, Stripe/Slack tokens) via the GitHub API. The attack also establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/g6-mobile (npm)
The npm account `atool` was compromised, leading to publication of 631 malicious versions across 314 npm packages including @antv/g6-mobile. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/g-webgl-compute (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-webgl-compute, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g6-plugin-map-view (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g6-plugin-map-view, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.
Mini Shai HuludnpmCompromised packageAccount takeover - containedcritical
Malicious code in tubebrain (npm)
The npm package tubebrain contained malicious code that exfiltrated environment variables and GitHub API interactions to an attacker-controlled domain (transscendsurvival.org). The package was identified by OpenSSF and published as a GitHub advisory.
npmCompromised package - resolvedcritical
Malicious code in superacli (npm)
The npm package superacli contained malicious code in plugins/gopass/daemon.js that established an unauthorized WebSocket connection to a hardcoded IP address (92.113.145.178:8768), allowing remote operators to execute arbitrary commands against the user's local gopass password store and exfiltrate decrypted secrets.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in skipshot-agent (npm)
The npm package skipshot-agent contained malicious code in its install script that exfiltrated environment variables to an attacker-controlled Cloudflare Workers endpoint. The package performed an unconditional POST request to https://edge-gateway.botmarket.workers.dev during installation, leaking process.env values including API keys, cloud credentials, and CI tokens.
npmCompromised package - containedcritical
Malicious code in swift-optimizer (npm)
swift-optimizer@1.1.0 on npm contains malicious postinstall code that fetches and executes a binary from Azure blob storage. The attack is targeted to specific organizations via hardcoded victim fingerprints derived from domain and hostname hashes.
npmCompromised packageMalicious commit - containedcritical
Malicious code in @antv/gi-assets-algorithm (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-assets-algorithm, in an automated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in your-unique-package-name1 (npm)
Malicious code in npm package your-unique-package-name1 exfiltrates authenticated Pendo session data from end users via hidden iframe and webhook beaconing. The package was identified by OpenSSF as a live attack rather than a contained proof-of-concept.
npmCompromised package - containedcritical
Malicious code in @antv/gi-sdk-app (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-sdk-app. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/l7-editor (npm)
The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-editor, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.
Mini Shai HuludnpmAccount takeoverCompromised package - containedcritical
Malicious code in gantt-for-react (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including gantt-for-react, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g6-extension-3d (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-extension-3d, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g2-ssr (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g2-ssr, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g6-plugin (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g6-plugin, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.
Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/gi-assets-basic (npm)
A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-assets-basic, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - activecritical
Malicious code in @antv/gi-assets-graphscope (npm)
A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/gi-assets-graphscope. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in ai-figure (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including ai-figure, in an automated attack. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/gi-assets-scene (npm)
The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-scene. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/gi-public-data (npm)
The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages in a 22-minute automated burst, part of the "Mini Shai-Hulud" supply chain attack campaign. @antv/gi-public-data was among the affected packages, modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/gi-sdk (npm)
A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-sdk, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure/Kubernetes credentials, SSH keys, Docker configs, database strings, Stripe/Slack tokens) via the GitHub API. The attack also establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package - resolvedcritical
Malicious code in @convera/ui-shared (npm)
The npm package @convera/ui-shared version 0.0.2 contained malicious code that exfiltrated system hostname and username during installation via a preinstall script. The package was published under a private namespace scope, creating a dependency-confusion attack surface against the Convera organization.
npmCompromised packageDependency confusion - containedcritical
Malicious code in @antv/interaction (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/interaction, in an automated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/gi-mock-data (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-mock-data, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - activecritical
Malicious code in @cap-js/openapi (npm)
The npm package @cap-js/openapi was compromised and found to contain malicious code. The package steals credentials and propagates them to other packages it has access to, with persistence mechanisms. This is attributed to the "Mini Shai-Hulud is back" worm campaign by the TeamPCP threat actor.
Mini Shai HuludTeamPCPnpmCompromised packageMalicious maintainer - containedcritical
Malicious code in @apps-home-dashboard/events (npm)
The npm package @apps-home-dashboard/events version 11.9.1 was found to contain malicious code that communicates with domains associated with malicious activity and executes suspicious commands. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.
npmCompromised package - activecritical
Malicious code in @antv/l7-scene (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-scene, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/li-editor (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/li-editor, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - activecritical
Malware in log-taker1
The npm package log-taker1 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malicious code in mcp-mermaid (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including mcp-mermaid, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in jest-canvas-mock (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including jest-canvas-mock, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - resolvedcritical
Malicious code in @pelmnaads/naads-common-logger (npm)
Malicious code in @pelmnaads/naads-common-logger (npm) version 19999.0.1 exploited dependency confusion by publishing to the public npm registry with an abnormally high version number. A preinstall script transmitted installer hostname data to a Burp Collaborator endpoint (h5nvwrz2815ubw84cpkwhezm5db9z1nq.b.mburpcollab.com), silently exfiltrating build host identity.
npmDependency confusionCompromised package - containedcritical
Malicious code in hardhat-core (npm)
The npm package hardhat-core v1.0.0 is a typosquat of the legitimate hardhat package that executes a malicious postinstall script. The script base64-decodes a URL, fetches a payload over plain HTTP from a hardcoded IP address, and pipes it directly into bash, executing arbitrary attacker-controlled code during installation.
npmTyposquattingCompromised package - activecritical
Malware in demo-awesome-date-parser-test
The npm package demo-awesome-date-parser-test contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - containedcritical
Malware in f0-fpti-tracking-manager
Malware was discovered in the npm package f0-fpti-tracking-manager. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - containedcritical
Malware in rainbokit
Malware was discovered in the npm package rainbokit, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in identityauthorizationserv
The npm package identityauthorizationserv was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in nemo-jaws
Malware was discovered in the npm package nemo-jaws, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.
npmCompromised package - containedcritical
Malware in fundraiserserv
Malware was discovered in the npm package fundraiserserv. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in xo-twofa
The npm package xo-twofa contained malware that fully compromised any system where it was installed. GitHub Security Advisory GHSA-7v73-c7c7-mr5x documents the incident as critical severity.
npmCompromised package - activecritical
Malware in xo-member-components
The npm package xo-member-components was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in filifecycleserv-paypal
Malware discovered in the npm package filifecycleserv-paypal. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in gpaas-paypal
The npm package gpaas-paypal was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in merchantprefsservice-paypal
Malware was discovered in the npm package merchantprefsservice-paypal. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in identityscimapiserv
Malware was discovered in the npm package identityscimapiserv. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in preferenceslifecycle-paypal
The npm package preferenceslifecycle-paypal contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in payoutsvettingserv-paypal
Malware discovered in the npm package payoutsvettingserv-paypal. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @immobiliarelabs/backstage-plugin-gitlab
Malware was discovered in the npm package @immobiliarelabs/backstage-plugin-gitlab. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in f0-data-constructor
Malware was discovered in the npm package f0-data-constructor. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in f0-form-manipulator
The npm package f0-form-manipulator was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @vinnxcode/xbailsync
The npm package @vinnxcode/xbailsync contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in riskunifiedgatewayserv
Malware was discovered in the npm package riskunifiedgatewayserv. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.
npmCompromised package - containedcritical
Malware in stargateproxyserv
The npm package stargateproxyserv was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in crm-reportinsightserv-paypal
Malware discovered in the npm package crm-reportinsightserv-paypal. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in pp-react-ui5
Malware was discovered in the npm package pp-react-ui5. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in tailwind-motionkit
The npm package tailwind-motionkit contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in route-processor
Malware discovered in the npm package route-processor. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @array-util/subsearch
Malware discovered in the npm package @array-util/subsearch. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @array-util/nodepull
Malware discovered in the npm package @array-util/nodepull. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in animated-css-kit
The npm package animated-css-kit contained malware that could fully compromise affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in gamified-trading-system
The npm package gamified-trading-system contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in font-huge
Malware discovered in the npm package font-huge. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in npx-whoami-demo
The npm package npx-whoami-demo was found to contain malware. Any system with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - activecritical
Malware in kalipto-runtime
Malware discovered in the npm package kalipto-runtime. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in fluterjs
Malware discovered in the npm package fluterjs. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @kalipto/local
The npm package @kalipto/local contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in gifuct
The npm package gifuct was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in svg-fetcher
Malware discovered in the npm package svg-fetcher. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in @my_name_is_khn/express-security-tool
The npm package @my_name_is_khn/express-security-tool contained malware that could fully compromise any system where it was installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.
npmCompromised package - containedcritical
Malware in @my_name_is_khn/express-security-tool-v2
The npm package @my_name_is_khn/express-security-tool-v2 contained malware that could fully compromise any system where it was installed or executed. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.
npmCompromised package - activecritical
Malware in express-timer
Malware discovered in the npm package express-timer. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @my_name_is_khn/express-security-tool-v3
The npm package @my_name_is_khn/express-security-tool-v3 contained malware that could fully compromise any system where it was installed or executed. The package has been identified and removed from distribution.
npmCompromised package - resolvedcritical
Malware in @my_name_is_khn/express-security-tool-v1
The npm package @my_name_is_khn/express-security-tool-v1 contained malware that could fully compromise any system where it was installed or executed. GitHub Security Advisory GHSA-v624-m435-vmfx documents the incident.
npmCompromised package - containedcritical
Malware in express-self-destruct
The npm package express-self-destruct contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malicious code in cheerio-tool (npm)
cheerio-tool, a typosquatting package on npm impersonating the popular cheerio HTML parser, contained malicious postinstall code that harvested npm credentials, API keys, cloud credentials, and cryptocurrency wallet data from infected systems.
npmTyposquattingCompromised package - activecritical
Malware in express-self-destruct2
Malware discovered in the npm package express-self-destruct2. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.
npmCompromised package - activecritical
Malware in express-self-destruct1
Malware discovered in the npm package express-self-destruct1. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.
npmCompromised package - containedcritical
Malware in @ceeferenderer/itg-renderer-sdk
Malware was discovered in the npm package @ceeferenderer/itg-renderer-sdk. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.
npmCompromised package - containedcritical
Malware in hardhat-compile-ethers
Malware was discovered in the npm package hardhat-compile-ethers, providing full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in @equansservices/tool
Malware was discovered in the npm package @equansservices/tool. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in supertokens-web
Malware was discovered in the supertokens-web npm package. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - containedcritical
Malware in tinymask-js
Malware was discovered in the npm package tinymask-js. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - activecritical
Malware in llama-tokenizer
The npm package llama-tokenizer contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in @sqlite-frame/nodesql
Malware discovered in the npm package @sqlite-frame/nodesql. Systems with this package installed are considered fully compromised and may have given outside entities complete control.
npmCompromised package - activecritical
Malware in @sqlite-tag/schema-generator
Malware was discovered in the npm package @sqlite-tag/schema-generator. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @sqlite-tag/sql-creator
The npm package @sqlite-tag/sql-creator was found to contain malware. Systems with this package installed are considered fully compromised, with potential for complete system takeover.
npmCompromised package - containedcritical
Malware in fazzanime
The npm package fazzanime was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in fazzgram
The npm package fazzgram contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in amanexzyra-baileys
The npm package amanexzyra-baileys contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @fazzcode/baileys
Malware was discovered in the npm package @fazzcode/baileys. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @ceeferenderer/fe-renderer-sdk
Malware was discovered in the npm package @ceeferenderer/fe-renderer-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @wrenfield/abitype
Malware discovered in the npm package @wrenfield/abitype. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @wrenfield/viem
The npm package @wrenfield/viem contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in @vinnxcode/libsignal-node
The npm package @vinnxcode/libsignal-node contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different system.
npmCompromised package - resolvedcritical
Malware in sixbails
The npm package sixbails was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in permcarmserver
The npm package permcarmserver was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in permcserver
The npm package permcserver contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in log-taker
The npm package log-taker contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in ts-escro
The npm package ts-escro was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in thirdwb
The npm package thirdwb contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in rainbownkit
Malware was discovered in the npm package rainbownkit, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.
npmCompromised package - containedcritical
Malware in thirdwebjs
The npm package thirdwebjs was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - containedcritical
Malware in thurdweb
The npm package thurdweb was compromised and distributed with malware, resulting in full system compromise for any installation. All secrets and keys on affected systems should be rotated immediately from a clean machine.
npmCompromised package - resolvedcritical
Malicious code in yessir-node (npm)
yessir-node, a malicious npm package, executes code on require() that modifies @whiskeysockets/baileys to force-subscribe authenticated WhatsApp accounts to attacker-controlled channels. The package masquerades as a libsignal implementation while performing destructive dependency tampering.
npmCompromised package - resolvedcritical
Malware in thirdwebb
The npm package thirdwebb contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in therdweb
Malware was discovered in the npm package therdweb, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in thidweb
The npm package thidweb was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in ts-escrow
Malware was discovered in the ts-escrow npm package. Systems with the package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.
npmCompromised package - containedcritical
Malware in polymarket-stake-maths
The npm package polymarket-stake-maths contained malware that could fully compromise any system where it was installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in chai-log
Malware discovered in the npm package chai-log. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @sqlite-frame/createsql
Malware was discovered in the npm package @sqlite-frame/createsql. Systems with this package installed are considered fully compromised, with potential for complete system takeover.
npmCompromised package - containedcritical
Malicious code in prisma-callback (npm)
prisma-callback@1.0.3 is a typosquatting package impersonating the legitimate Prisma ORM. It contains a preinstall script that executes undeclared, opaque native Go binaries (prisma-amd64 or prisma-arm64) at install time without integrity verification.
npmTyposquattingCompromised package - resolvedcritical
Malicious code in prettier-lint-lenz (npm)
The npm package prettier-lint-lenz is a malicious imposter of the legitimate Prettier formatter. It executes a postinstall script that deploys clipboard-stealing malware on Windows systems, establishing persistence via a scheduled task that exfiltrates clipboard contents to a hardcoded C2 server.
npmCompromised packageTyposquatting - containedcritical
Malware in txs-sdk-lib
Malware was discovered in the npm package txs-sdk-lib, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in txs-random-lib
Malware discovered in the npm package txs-random-lib. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in txs-runner-lib
Malware was discovered in the npm package txs-runner-lib, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in txs-builder
The npm package txs-builder was found to contain malware, potentially giving outside entities full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in v018-axios-cdntest
The npm package v018-axios-cdntest contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in edu-npm-helper-alpha
Malware was discovered in the npm package edu-npm-helper-alpha. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in edu-npm-helper-beta
Malware was discovered in the npm package edu-npm-helper-beta. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - resolvedcritical
Malware in edu-npm-postinstall-demo2
Malware was discovered in the npm package edu-npm-postinstall-demo2. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.
npmCompromised package - activecritical
Malware in edu-npm-dependency-chain-demo
Malware discovered in the npm package edu-npm-dependency-chain-demo. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in roblox-api-client
Malware was discovered in the npm package roblox-api-client, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.
npmCompromised package - activecritical
Malware in @thone33/analytics-injector
Malware discovered in the npm package @thone33/analytics-injector. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @thone33/react-helpers
Malware was discovered in the npm package @thone33/react-helpers, granting full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in @thone33/core-utils
Malware was discovered in the npm package @thone33/core-utils, granting full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in @403name/fsevent
Malware discovered in the npm package @403name/fsevent. Systems with this package installed are considered fully compromised with potential for complete system control by an external entity.
npmCompromised package - activecritical
Malware in @403name/ether-js
Malware was distributed via the npm package @403name/ether-js. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - resolvedcritical
Malware in @403name/electron-buidler
The npm package @403name/electron-buidler contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different machine.
npmCompromised package - activecritical
Malware in ap3-components-ui
Malware discovered in the npm package ap3-components-ui. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malicious code in node-ci-utils (npm)
The npm package node-ci-utils contained malicious code that, on require(), downloads and executes an unsigned binary from attacker-controlled infrastructure. The package used obfuscation techniques (base64-encoded URL, single-letter variables) to evade detection.
npmCompromised package - containedcritical
Malware in jextic-eclib
Malware was discovered in the npm package jextic-eclib, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malicious code in exxpress-utils (npm)
The npm package exxpress-utils contained malicious code in a postinstall script that harvested npm/AWS/GitHub credentials, scanned for cryptocurrency wallet extensions, and exfiltrated sensitive files to a hardcoded C2 server. The package was a typosquat of the legitimate 'express' package.
npmCompromised packageTyposquatting - containedcritical
Malicious code in sysbin (npm)
The npm package sysbin contains malicious code that executes a Python stealth overlay (pointer.py) on installation or require(), exfiltrating clipboard contents and screenshots to a hardcoded attacker endpoint. The package includes a 'ghost installer' that silently installs Python if absent, bypassing user prompts.
npmCompromised package - resolvedcritical
Malware in @ci-lifecycle-test/postinstall-ping
Malware was distributed via the npm package @ci-lifecycle-test/postinstall-ping. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malicious code in typography-stylecss (npm)
The npm package typography-stylecss is a typosquatting attack impersonating the legitimate @tailwindcss/typography plugin. It contains obfuscated malicious code that downloads and executes a platform-specific binary when the module is imported, triggered automatically during Tailwind config loading.
npmTyposquattingCompromised package - containedcritical
Malicious code in solc-helper (npm)
The npm package solc-helper version 2.0.0 contains malicious code in its postinstall lifecycle script that downloads and executes arbitrary shell code from an attacker-controlled server. Every installation triggers an unattended download-and-execute of remote code via curl piped to bash from a bare IP address over plaintext HTTP.
npmCompromised package - containedcritical
Malicious code in pinno-loggers (npm)
pinno-loggers is a malicious npm package that depends on terminal-logger-utils and executes a multi-stage malware payload via postinstall hooks. The second-stage binary provides keylogger, infostealer, and RAT capabilities, stealing sensitive data including credentials, SSH keys, and crypto wallets.
npmCompromised packageMalicious commit - containedcritical
Malicious code in polymarket-auto-trade (npm)
A coordinated supply-chain attack published 9 malicious npm packages under the polymarketdev maintainer on 2026-05-20, masquerading as Polymarket CLOB trading tools. The packages exfiltrate Ethereum private keys via postinstall hooks to a Cloudflare Worker C2 endpoint, with adaptive evasion for CI/CD scanners.
npmCompromised packageMalicious maintainer - containedcritical
Malicious code in polymarket-trader (npm)
A coordinated supply-chain attack published 9 malicious npm packages by maintainer polymarketdev on 2026-05-20, masquerading as Polymarket CLOB trading tools. The packages exfiltrate Ethereum private keys via postinstall hooks to a Cloudflare Worker C2 endpoint, with evasion techniques targeting CI/CD scanners.
npmMalicious maintainerCompromised package - containedcritical
Malicious code in polymarket-terminal (npm)
A coordinated supply-chain attack published 9 malicious npm packages by maintainer polymarketdev on 2026-05-20, masquerading as Polymarket CLOB trading tools. The packages exfiltrate Ethereum private keys via postinstall hooks to a Cloudflare Worker C2 endpoint, with adaptive evasion for CI/CD scanners and silent extraction from .env files.
npmMalicious maintainerCompromised package - resolvedcritical
Malicious code in @akunsansan0/pucuk9 (npm)
The npm package @akunsansan0/pucuk9 contained malicious code designed to automatically generate and publish derivative packages with randomized names to the npm registry. The package was part of a broader campaign to inflate developer reputation scores for tea protocol token rewards.
npmCompromised package - containedcritical
Malicious code in @antv/g-css-layout-api (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-css-layout-api, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/dw-util (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/dw-util, each injecting a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via GitHub API. The attack also establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - resolvedcritical
Malicious code in @akunsansan0/teagunz99 (npm)
@akunsansan0/teagunz99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.
npmCompromised package - containedcritical
Malicious code in @angular_devkit/core (npm)
Version 99.1.1 of @angular_devkit/core (npm) was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.
npmCompromised package - containedcritical
Malicious code in @antstackio/shelbysam (npm)
The npm package @antstackio/shelbysam was compromised and contained malicious code associated with the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates to other NPM packages owned by the user, and may destroy the user's home directory.
Shai-HuludnpmCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-plugin-webgpu-device (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-webgpu-device, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/g-dom-mutation-observer-api (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-dom-mutation-observer-api, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.
Mini Shai HuludnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/data-samples (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/data-samples. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-plugin-mobile-interaction (npm)
A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-mobile-interaction, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/dw-transform (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/dw-transform. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/f6-hammerjs (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f6-hammerjs, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.
Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/f2-algorithm (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f2-algorithm, in a coordinated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-plugin-webgl-device (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-webgl-device, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/f2-my (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f2-my, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-plugin-yoga (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-plugin-yoga, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-plugin-css-select (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-css-select, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/chart-visualization-skills (npm)
The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/chart-visualization-skills, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/g-plugin-annotation (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-annotation. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
npmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-web-components (npm)
A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/g-web-components. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-plugin-svg-picker (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-svg-picker, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - resolvedcritical
Malicious code in @akunsansan0/pucuk11 (npm)
@akunsansan0/pucuk11 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and pollutes the npm registry with variants.
npmCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-camera-api (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-camera-api. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - resolvedcritical
Malicious code in @alaska-its/design-tokens (npm)
Malicious code was discovered in the npm package @alaska-its/design-tokens. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-56q2-v4w4-rwhm.
npmCompromised package - containedcritical
Malicious code in @antv/g-css-typed-om-api (npm)
The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages in an automated attack. @antv/g-css-typed-om-api was among the affected packages, modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/data-set (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/data-set. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/f2-wordcloud (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f2-wordcloud, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/chart-linter (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/chart-linter, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure credentials, SSH keys, Docker configs, database strings, API keys) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antstackio/express-graphql-proxy (npm)
The npm package @antstackio/express-graphql-proxy was compromised and contained malicious code as part of the Sha1-Hulud: The Second Coming NPM worm. The malware steals tokens and credentials, publishes them to GitHub, propagates to other packages owned by the user, and may destroy the user's home directory.
Shai-HuludnpmCompromised packageMalicious commit - containedcritical
Malicious code in @antv/f2-site (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/f2-site, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmCompromised packageAccount takeover - containedcritical
Malicious code in @antstackio/json-to-graphql (npm)
The npm package @antstackio/json-to-graphql was compromised and contained malicious code as part of the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates to other npm packages owned by the user, and may destroy the user's home directory.
Shai-HuludnpmCompromised packageMalicious commit - containedcritical
Malicious code in @antv/dipper-component (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/dipper-component, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-pattern (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-pattern, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - resolvedcritical
Malicious code in @amber-team/react-modal-stack (npm)
The npm package @amber-team/react-modal-stack was found to contain malicious code. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Security Advisory GHSA-44rm-8vq6-qhf5.
npmCompromised package - containedcritical
Malicious code in @andes-tools/colors (npm)
The npm package @andes-tools/colors version 999.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.
npmCompromised package - resolvedcritical
Malicious code in @amiga-fwk-nodejs/log (npm)
The npm package @amiga-fwk-nodejs/log was found to contain malicious code. The package has been identified and documented by the OpenSSF malicious packages project.
npmCompromised package - containedcritical
Malicious code in @antv/g-device-api (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-device-api. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-plugin-dom-interaction (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-dom-interaction, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmAccount takeoverCompromised package - resolvedcritical
Malicious code in @anchor-ds/core (npm)
The npm package @anchor-ds/core was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.
npmCompromised package - resolvedcritical
Malicious code in @amber-team/gatsby-plugin-semcore (npm)
The npm package @amber-team/gatsby-plugin-semcore was found to contain malicious code. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-27jr-546m-cv6p.
npmCompromised package - resolvedcritical
Malicious code in @al-ui/useappinsights (npm)
Malicious code was discovered in the npm package @al-ui/useappinsights. The package was identified by the OpenSSF malicious-packages project as containing malicious code.
npmCompromised package - resolvedcritical
Malicious code in @akunsansan0/susu2 (npm)
@akunsansan0/susu2 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to the npm registry. The package was part of a tea.xyz token reward campaign that flooded npm with similar malicious packages.
npmCompromised package - containedcritical
Malicious code in @antv/dipper-hooks (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/dipper-hooks, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - resolvedcritical
Malicious code in @angular_devkit/build_angular (npm)
Malicious code was discovered in the npm package @angular_devkit/build_angular. The compromised package contained code that communicates with a domain associated with malicious activity. The incident was identified and reported by the OpenSSF malicious packages project.
npmCompromised package - containedcritical
Malicious code in @angular_devkit/architect (npm)
Malicious code was discovered in the npm package @angular_devkit/architect. The package contained code that communicates with a domain associated with malicious activity. The incident was identified and reported by the OpenSSF malicious packages project.
npmCompromised package - resolvedcritical
Malicious code in @alphasedboy/game (npm)
Malicious code was discovered in the npm package @alphasedboy/game. The package was flagged by the OpenSSF malicious-packages project and assigned advisory GHSA-9587-gmc9-6qh8.
npmCompromised package - resolvedcritical
Malicious code in @aluffyz/discord-botjs (npm)
The npm package @aluffyz/discord-botjs version 1.4.5 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.
npmCompromised package - containedcritical
Malicious code in @akunsansan0/tehpucuk1 (npm)
@akunsansan0/tehpucuk1 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.
npmMalicious commitCompromised package - resolvedcritical
Malicious code in @akunsansan0/tea_guntry99 (npm)
@akunsansan0/tea_guntry99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in @amiga-fwk-nodejs/metrics (npm)
The npm package @amiga-fwk-nodejs/metrics was found to contain malicious code. The package has been identified and reported by the OpenSSF malicious packages project.
npmCompromised package - resolvedcritical
Malicious code in @akunsansan0/teagunup99 (npm)
@akunsansan0/teagunup99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in @akunsansan0/karedok36 (npm)
@akunsansan0/karedok36 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.
npmCompromised packageMalicious commit - containedcritical
Malicious code in @antv/data-wizard (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/data-wizard. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-plugin-physx (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-plugin-physx, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - resolvedcritical
Malicious code in @akunsansan0/tea_gunt99 (npm)
@akunsansan0/tea_gunt99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in @alexandrsarioglo/npm-ghost-htb (npm)
The npm package @alexandrsarioglo/npm-ghost-htb was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.
npmCompromised package - resolvedcritical
Malicious code in @akunsansan0/susu8 (npm)
@akunsansan0/susu8 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modifies package.json, removes private flags, and pollutes the npm registry with variants.
npmCompromised package - resolvedcritical
Malicious code in @antstackio/eslint-config-antstack (npm)
The npm package @antstackio/eslint-config-antstack was compromised and contained malicious code as part of the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates itself to other NPM packages owned by the user, and may destroy the user's home directory.
Shai-HuludnpmCompromised packageMalicious commit - resolvedcritical
Malicious code in @aligntech-cw/alignerfit (npm)
Malicious code was discovered in the npm package @aligntech-cw/alignerfit. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-1743.
npmCompromised package - resolvedcritical
Malicious code in @akunsansan0/susu10 (npm)
@akunsansan0/susu10 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to the npm registry. The package was part of a tea.xyz token reward campaign that flooded npm with similar malicious packages.
npmCompromised package - containedcritical
Malicious code in @antv/f2-canvas (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/f2-canvas, each injecting a preinstall hook that executes an obfuscated Bun script to exfiltrate credentials and establish persistence. The attack was part of the "Mini Shai-Hulud" supply chain attack campaign.
Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package - resolvedcritical
Malicious code in @akunsansan0/susu11 (npm)
@akunsansan0/susu11 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, changes version numbers, and continuously pollutes the npm registry with variants.
npmCompromised package - resolvedcritical
Malicious code in @akunsansan0/susu3 (npm)
@akunsansan0/susu3 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.
npmCompromised package - containedcritical
Malicious code in @andrewstory18/is-real-odd (npm)
@andrewstory18/is-real-odd is a malicious npm package that impersonates the legitimate is-odd package by copying its metadata, but includes an obfuscated postinstall script that exfiltrates data to a hardcoded attacker IP (144.172.91.84:3000) on installation.
npmCompromised packageTyposquatting - resolvedcritical
Malicious code in @anhackle/test (npm)
The npm package @anhackle/test was found to contain malicious code. The package has been identified and cataloged by the OpenSSF malicious packages project.
npmCompromised package - containedcritical
Malicious code in @antv/f-wx (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f-wx. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - resolvedcritical
Malicious code in @akunsansan0/kopi3 (npm)
@akunsansan0/kopi3 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.
npmCompromised package - containedcritical
Malicious code in @antv/g-plugin-webgl-renderer (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-webgl-renderer, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmAccount takeoverCompromised package - resolvedcritical
Malicious code in @amber-team/figma-utils (npm)
The npm package @amber-team/figma-utils was found to contain malicious code. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Advisory GHSA-2j44-84pc-388j.
npmCompromised package - resolvedcritical
Malicious code in @amigatechdocs/core (npm)
The npm package @amigatechdocs/core was found to contain malicious code. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2025-42187.
npmCompromised package - containedcritical
Malicious code in @antv/g-web-animations-api (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-web-animations-api. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-plugin-matterjs (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-matterjs, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @amops/fetch (npm)
The npm package @amops/fetch version 1.4.1 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.
npmCompromised package - resolvedcritical
Malicious code in @amber-team/export-events-to-sheet (npm)
The npm package @amber-team/export-events-to-sheet was found to contain malicious code. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-qxj3-92mx-9r8w.
npmCompromised package - containedcritical
Malicious code in @antv/g-plugin-zdog-canvas-renderer (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-zdog-canvas-renderer, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmAccount takeoverCompromised package - containedcritical
Malicious code in @angular_devkit/build-webpack (npm)
The npm package @angular_devkit/build-webpack version 99.1.1 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.
npmCompromised package - containedcritical
Malicious code in @antv/g-layout-blocklike (npm)
The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages in an automated attack known as "Mini Shai-Hulud." The @antv/g-layout-blocklike package was among those modified to inject a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-perf (npm)
The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-perf. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-plugin-zdog-svg-renderer (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-zdog-svg-renderer, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure credentials, SSH keys, Docker configs, database strings, API keys) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/f6-alipay (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f6-alipay, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/d3-interpolate (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/d3-interpolate, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-plugin-box2d (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-box2d, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/awards (npm)
A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/awards, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - resolvedcritical
Malicious code in @akunsansan0/pucuk12 (npm)
@akunsansan0/pucuk12 on npm contained malicious code designed to automatically generate and publish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modified package.json, changed version numbers, and continuously republished variants to pollute the npm registry.
npmCompromised package - containedcritical
Malicious code in @antv/f-charts (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f-charts, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.
Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/f2-wx (npm)
The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f2-wx, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/calendar-heatmap (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/calendar-heatmap, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-compat (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-compat. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/f-my (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/f-my. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-plugin-canvas-picker (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-canvas-picker. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.
Mini Shai HuludnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/g-plugin-canvaskit-renderer (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-canvaskit-renderer, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.
Mini Shai HuludnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/dipper-map (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/dipper-map, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmAccount takeoverCompromised package - containedcritical
Malicious code in @antv/f6-wx (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f6-wx. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
TeamPCPMini Shai HuludnpmAccount takeoverCompromised package - resolvedhigh
Malicious code in @akunsansan0/tehpucuk2 (npm)
@akunsansan0/tehpucuk2 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in @akunsansan0/karedok4 (npm)
@akunsansan0/karedok4 on npm contained malicious code designed to automatically generate and publish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modified package.json, changed version numbers, and continuously republished variants to pollute the npm registry.
npmCompromised package - resolvedcritical
Malicious code in @akunsansan0/teaguntur99 (npm)
@akunsansan0/teaguntur99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in @akunsansan0/pucukharum (npm)
@akunsansan0/pucukharum is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to the npm registry. The package was part of a tea.xyz token reward campaign that flooded npm with similar malicious packages.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main (npm)
Malicious code was published in the npm package "-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main". The package was identified and cataloged by the OpenSSF malicious packages database.
npmCompromised package - resolvedcritical
Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-espanol (npm)
A malicious npm package named "-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-espanol" was published containing malicious code. The package was identified and documented by the OpenSSF malicious packages project.
npmCompromised package - resolvedcritical
Malicious code in -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love (npm)
A malicious npm package with a deceptive name containing movie-related keywords was published to the npm registry. The package contained malicious code and was identified by the OpenSSF malicious packages project.
npmCompromised package - resolvedcritical
Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-love (npm)
A malicious npm package named "-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-love" was published containing malicious code. The package was identified and documented by the OpenSSF malicious packages project.
npmCompromised package - resolvedcritical
Malicious code in -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-suparhit (npm)
A malicious npm package with a typosquatting name was published containing malicious code. The package was identified and cataloged by the OpenSSF malicious packages project.
npmCompromised package - resolvedcritical
Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-espanol (npm)
Malicious code was published in an npm package with a deceptive name referencing a John Wick movie. The package was identified and cataloged by the OpenSSF malicious packages database.
npmCompromised package - containedcritical
Malicious code in -pem-misa (npm)
The npm package -pem-misa contains malicious code designed to automatically generate and republish derivative packages with randomized names to the npm registry. The attack is part of a broader tea.xyz token reward campaign that flooded npm with similar malicious packages.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-tarabi-lliena- (npm)
Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and cataloged by the OpenSSF malicious packages database.
npmCompromised package - resolvedcritical
Malicious code in -accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena- (npm)
A malicious npm package with an obfuscated name containing Spanish-language movie references was published to npm. The package contained malicious code and was identified by the OpenSSF malicious packages project.
npmCompromised package - resolvedcritical
Malicious code in -espanol-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love (npm)
A malicious npm package named "-espanol-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love" was published containing malicious code. The package was identified and documented by the OpenSSF malicious packages project.
npmCompromised package - resolvedcritical
Malicious code in -whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home (npm)
Malicious code was published in the npm package "-whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home". The package was identified and cataloged by the OpenSSF malicious packages project.
npmCompromised package - resolvedcritical
Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena- (npm)
Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and documented by the OpenSSF malicious packages project.
npmCompromised package - resolvedcritical
Malicious code in -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena- (npm)
Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and cataloged by the OpenSSF malicious packages database.
npmCompromised package - resolvedcritical
Malicious code in -john-wick-4-keanu-reeves-pelicula-completa-h-d-varindo-en-casa-en-lienia-lliena-love (npm)
A malicious npm package with a deceptive movie-themed name was published to the npm registry. The package contained malicious code and was identified by the OpenSSF malicious packages project.
npmCompromised package - resolvedcritical
Malicious code in -espanol-john-wick-keanu-reeves-4-k-varindo-en-casa-en-lienia-lliena-love (npm)
A malicious npm package with a typosquatting name containing Spanish text and movie references was published to npm. The package contained malicious code and was identified by the OpenSSF malicious packages project.
npmCompromised package - resolvedcritical
Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-en-lienia-lliena-love (npm)
A malicious npm package with a deceptive movie-themed name was published containing malicious code. The package was identified and documented by the OpenSSF malicious packages database.
npmCompromised package - resolvedcritical
Malicious code in -john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love (npm)
Malicious code was published in the npm package "-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love". The package was identified by the OpenSSF malicious-packages project and reported via GitHub Advisory GHSA-7x55-g6gw-jq49.
npmCompromised package - resolvedcritical
Malicious code in -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-123 (npm)
Malicious code was published in the npm package "-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-123". The package was identified and cataloged by the OpenSSF malicious packages project.
npmCompromised package - resolvedcritical
Malicious code in -accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-allah-varindo-en-casa-lliena- (npm)
Malicious code was published in an npm package with a deceptive name mimicking movie content. The package was identified and cataloged by the OpenSSF malicious packages database.
npmCompromised package - resolvedcritical
Malicious code in -john-wick-4-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love (npm)
A malicious npm package with a deceptive name containing movie-related keywords was published to the npm registry. The package contained malicious code and was identified and documented by the OpenSSF malicious packages project.
npmCompromised package - activecritical
Malware in app-data-layer
The npm package app-data-layer was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials
PyPI package mrmustard version 0.7.4 was compromised with malicious code that stole SSH keys, AWS credentials, and Kubernetes credentials upon import. The malicious version has been removed from PyPI.
PyPICompromised package - containedcritical
Malware in app-data-ist
The npm package app-data-ist was found to contain malware, potentially giving full control of affected systems to an outside entity. All systems with this package installed should be considered fully compromised.
npmCompromised package - containedcritical
Malware in app-node-layer
Malware was discovered in the npm package app-node-layer. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in app-data-lts
The npm package app-data-lts was found to contain malware, potentially giving full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in vitest-axios
The npm package vitest-axios contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in @bcryptln/bcryptjs
The npm package @bcryptln/bcryptjs contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in lychee-norm-cache
Malware discovered in the npm package lychee-norm-cache. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in ethers-packge
The npm package ethers-packge contained malware that compromised any system where it was installed. Systems with this package should be considered fully compromised and all secrets and keys rotated from a different computer.
npmCompromised package - activecritical
Malware in svgcraft-core
Malware discovered in the npm package svgcraft-core. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in eth-codergen
Malware was discovered in the npm package eth-codergen. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in eth-slint
Malware was discovered in the eth-slint npm package. Systems with the package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in svelte-streak-metrics
Malware was discovered in the npm package svelte-streak-metrics. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in ethers-wallet-package
Malware was discovered in the npm package ethers-wallet-package, potentially providing full system compromise to attackers. All systems with this package installed should be considered fully compromised and all secrets and keys rotated from a different computer.
npmCompromised package - containedcritical
Malware in create-kumo-project
Malware was discovered in the npm package create-kumo-project. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in helix-deploy
Malware discovered in the npm package helix-deploy. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in eth-base
Malware was discovered in the eth-base npm package. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys at risk.
npmCompromised package - activecritical
Malware in aio-commerce-lib-app
Malware discovered in the npm package aio-commerce-lib-app. Any system with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in mcp-notes-server-poc-praetorian
The npm package mcp-notes-server-poc-praetorian contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malicious code in intercom-php (Packagist)
The intercom-php package on Packagist was compromised with malicious code as part of the Mini Shai-Hulud campaign by the TeamPCP threat actor. The malicious payload steals credentials and can propagate to NPM packages using discovered credentials.
Mini Shai HuludTeamPCPNuGetCompromised packageMalicious maintainer - activecritical
Malware in xrblocks-remote-control
The npm package xrblocks-remote-control contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in cktool-core
Malware was discovered in the npm package cktool-core. Systems with the package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in base65-85x
The npm package base65-85x was found to contain malware, potentially giving full control of affected systems to an outside entity. All systems with this package installed should be considered fully compromised.
npmCompromised package - containedcritical
Malware in fs-extra-core
Malware was discovered in the npm package fs-extra-core. Systems with this package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - activecritical
Malware in bs58-88
The npm package bs58-88 contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in vue-demi-fix
Malware was discovered in the npm package vue-demi-fix, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.
npmCompromised package - containedcritical
Malware in da-sc-sdk
Malware was discovered in the npm package da-sc-sdk. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.
npmCompromised package - activecritical
Malware in @bcryptln/becryptjs
Malware discovered in the npm package @bcryptln/becryptjs. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in streak-lib-math
Malware was discovered in the npm package streak-lib-math. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in streak-bucket-lib
The npm package streak-bucket-lib was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and all secrets/keys rotated from a clean machine.
npmCompromised package - containedcritical
Malware in svelte-goal-streak
Malware was discovered in the npm package svelte-goal-streak. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in ethers-wallet-packages
Malware was discovered in the npm package ethers-wallet-packages. Systems with this package installed are considered fully compromised and all secrets and keys should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in eslint-angular-react
The npm package eslint-angular-react contained malware that could fully compromise any system where it was installed or executed. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in yuinpm
The npm package yuinpm was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in chai-as-stringify
Malware discovered in the npm package chai-as-stringify. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in vantora
The npm package vantora contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in react-tabulix-ui
Malware discovered in the npm package react-tabulix-ui. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in encrypt-string-ttak
The npm package encrypt-string-ttak contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in calvora
Malware was discovered in the npm package calvora, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in react-tabulix-core
Malware was discovered in the npm package react-tabulix-core. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in calmora
The npm package calmora was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-7wwx-476f-c8gm documents the incident.
npmCompromised package - containedcritical
Malware in react-tabulix-query
Malware was discovered in the npm package react-tabulix-query. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in encryptstringadmin
The npm package encryptstringadmin was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in caldryn
Malware was discovered in the npm package caldryn, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in veldora
The npm package veldora contained malware that provided full system compromise to attackers. Any system with the package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in kijai
The npm package kijai was found to contain malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in vectormark
The npm package vectormark contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in fastify-bundler
Malware was discovered in the npm package fastify-bundler, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.
npmCompromised package - resolvedcritical
Malware in veskr
The npm package veskr contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in encryptstringadmincore
Malware discovered in the npm package encryptstringadmincore. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malicious code in adsplit (PyPI)
The adsplit package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adv2099m3 (PyPI)
Malicious code was discovered in the adv2099m3 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in xolonavrylpbeb (PyPI)
Malicious code was discovered in the xolonavrylpbeb package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-41797.
PyPICompromised package - resolvedcritical
Malicious code in yfinane (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinane, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in xorg-renderproto (PyPI)
Malicious code was discovered in the xorg-renderproto package on PyPI. The package contained intentional malicious functionality and was identified by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in xolofyxkotqwko (PyPI)
Malicious code was discovered in the PyPI package xolofyxkotqwko. The package was identified and reported by the OpenSSF malicious-packages project.
PyPICompromised package - containedcritical
Malicious code in xxx-bale (PyPI)
The PyPI package xxx-bale contained malicious code designed to download and execute remotely stored malware with persistence mechanisms. The malicious payload requires a separate trigger to activate.
2025 07 Cas Base CampaignPyPICompromised package - resolvedhigh
Malicious code in yeshsurya (PyPI)
The yeshsurya package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.
PyPICompromised package - resolvedcritical
Malicious code in yelp-cgeom1 (PyPI)
The PyPI package yelp-cgeom1 version 0.1 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.
PyPICompromised package - resolvedcritical
Malicious code in yffinance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yffinance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in admine (PyPI)
The PyPI package 'admine' contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in zyqnuutupjerllnbxaeq (PyPI)
Malicious code was published in the zyqnuutupjerllnbxaeq package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in xolosamsdyhcfa (PyPI)
Malicious code was discovered in the xolosamsdyhcfa package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in yfinnance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinnance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in yfnance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfnance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in yfinancce (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinancce, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in yfinnace (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinnace, which infected local browsers with a malicious extension designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - containedcritical
Malicious code in xyq-drama-skill (PyPI)
xyq-drama-skill, a PyPI package, contained malicious code that downloads and executes an unsigned binary from a remote server during installation and on command invocation. The package masquerades as a Chinese short-video drama script generator but actually deploys what appears to be a COFFLoader beacon.
PyPICompromised packageMalicious commit - resolvedcritical
Malicious code in yfinnce (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinnce, which infected local browsers with a malicious extension designed to manipulate the clipboard and replace cryptocurrency wallet addresses. The incident was identified and documented by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in yellyproxies (PyPI)
Malicious code was discovered in the yellyproxies package on PyPI. The package contained malicious functionality that could compromise systems of users who installed it.
PyPICompromised package - resolvedcritical
Malicious code in ai-cypher (PyPI)
The ai-cypher package on PyPI contained malicious code in a compiled native extension that exfiltrates sensitive Telegram files upon import. The package was identified and cataloged by the OpenSSF malicious-packages project.
2025 12 AI CypherPyPICompromised package - resolvedcritical
Malicious code in yfiinance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfiinance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in yfinacne (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinacne, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - containedhigh
Malicious code in yhaplo1 (PyPI)
Malicious package yhaplo1 was published to PyPI as a dependency confusion attack. The package contained code to exfiltrate basic system information but did not perform active exfiltration. The attacker identified themselves as a HackerOne user conducting a bug bounty test.
PyPIDependency confusionCompromised package - resolvedcritical
Malicious code in yfinannce (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinannce, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - containedcritical
Malicious code in yeahmankema (PyPI)
Malicious code was published in the yeahmankema package on PyPI. The package exfiltrates screenshots and network information to a hardcoded target, functioning as spyware.
2026 05 CrayrandomizPyPICompromised package - resolvedcritical
Malicious code in yfiannce (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfiannce, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in yfinaance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinaance, which infected local browsers with a malicious extension designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in yc-as-client (PyPI)
The PyPI package yc-as-client version 11.11.3 was identified as malicious by the OpenSSF Package Analysis project. The malicious code communicates with a domain associated with malicious activity.
PyPICompromised package - resolvedcritical
Malicious code in xxoo-bale (PyPI)
The PyPI package xxoo-bale contained malicious code designed to download and execute remotely stored malware with persistence mechanisms. The malicious payload required a separate trigger to activate.
2025 07 Cas BasePyPICompromised package - resolvedcritical
Malicious code in xxlsxwriter (PyPI)
Malicious code was distributed in the xxlsxwriter package on PyPI as part of a campaign distributing 900+ malicious packages. The malicious versions installed browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedhigh
Malicious code in yc-depconf-test-807dff (PyPI)
The PyPI package yc-depconf-test-807dff contains malicious code that exfiltrates basic host information (IP address, username) upon installation or module import. The package overrides the install command in setup.py to execute the malicious payload during installation.
PyPICompromised package - resolvedcritical
Malicious code in yfinace (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinace, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in yfinancee (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinancee, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in ytorch (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including ytorch, designed to infect local browsers with malicious extensions. The malicious extension manipulates clipboard content and replaces cryptocurrency wallet addresses to redirect funds to attacker-controlled wallets.
PyPICompromised package - containedcritical
Malicious code in yolov8mini (PyPI)
The yolov8mini package on PyPI contained malicious code that automatically launches a Telegram bot capable of stealing browser passwords, executing arbitrary commands, and exfiltrating data. The package was identified as part of a 2025-03 malicious campaign and has been reported to the OpenSSF malicious packages database.
PyPICompromised package - resolvedcritical
Malicious code in ython-binance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including ython-binance, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised packageTyposquatting - resolvedcritical
Malicious code in yvper (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yvper, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in yyfinance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yyfinance, which infected local browsers with a malicious extension designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - containedcritical
Malicious code in yuzo (PyPI)
The yuzo package on PyPI contained malicious code implementing an infostealer (CStealer-based) designed to exfiltrate browser data and other sensitive information to a hardcoded Discord webhook. Multiple versions of the package were affected with varying implementations of the malware.
2025 09 SuyoPyPICompromised package - resolvedcritical
Malicious code in yfniance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfniance, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in youtube-new (PyPI)
Malicious code was discovered in the youtube-new package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-41801.
PyPICompromised package - resolvedcritical
Malicious code in youreallydontwantthispackage2132 (PyPI)
Malicious code was published in the PyPI package youreallydontwantthispackage2132 version 1.0.3. The package executes malicious code during installation via setup.py override and communicates with domains associated with malicious activity, exfiltrating environment variables and other data.
PyPICompromised packageTyposquatting - resolvedcritical
Malicious code in ypcodestyle (PyPI)
Malicious code was distributed in the ypcodestyle package on PyPI as part of a campaign distributing 900+ compromised packages. The malware installs a malicious browser extension designed to manipulate the clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in yzip (PyPI)
The yzip package on PyPI contained malicious code that downloads and executes multi-stage malware during archive-support class initialization. The malware exhibits obfuscation and infosteal capabilities, tracked as campaign 2025-11-uzip.
2025 11 UzipPyPICompromised package - resolvedcritical
Malicious code in zafira (PyPI)
Malicious code was discovered in the zafira package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6252.
PyPICompromised package - resolvedcritical
Malicious code in ypsocks (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including ypsocks, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedhigh
Malicious code in your-module-name (PyPI)
The your-module-name package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.
PyPICompromised package - resolvedcritical
Malicious code in yper (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yper, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedhigh
Malicious code in yt-yson-bindings (PyPI)
The yt-yson-bindings package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.
PyPICompromised package - resolvedcritical
Malicious code in ziggonext (PyPI)
Malicious code was discovered in the ziggonext package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-6623.
PyPICompromised package - resolvedcritical
Malicious code in zamino (PyPI)
The PyPI package zamino was identified as malicious code—a clone of legitimate Aminoapps libraries with added credential exfiltration functionality. The package was part of the 2025-06-sorex campaign and has been cataloged by the OpenSSF malicious packages database.
2025 06 SorexPyPICompromised packageTyposquatting - resolvedcritical
Malicious code in zlapp (PyPI)
Malicious code was discovered in the zlapp package on PyPI. The package contained intentional malicious functionality and was identified by the OpenSSF malicious packages project.
PyPICompromised package - activecritical
Malicious code in zhopaorlaaato (PyPI)
The PyPI package zhopaorlaaato contains malicious code that runs an infostealer targeting Telegram and Discord credentials. Depending on version, the infostealer is either embedded in the package or downloaded from a remote URL for execution.
PyPICompromised package - resolvedcritical
Malicious code in zatta (PyPI)
Malicious code was discovered in the zatta package on PyPI. The package was flagged by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6253.
PyPICompromised package - resolvedhigh
Malicious code in zip-me (PyPI)
The PyPI package zip-me contained malicious code designed to exfiltrate system information including IP address and username. The malware was activated during package installation via a metaclass override in setup.py and employed VM-detection techniques to avoid analysis.
2024 12 Langer UpdaterPyPICompromised package - resolvedcritical
Malicious code in zefkopzekfo (PyPI)
Malicious code was discovered in the zefkopzekfo package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6254.
PyPICompromised package - resolvedcritical
Malicious code in zhpt1cscoe (PyPI)
Malicious code was discovered in the zhpt1cscoe package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6257.
PyPICompromised package - resolvedcritical
Malicious code in zelixnitro (PyPI)
Malicious code was discovered in the zelixnitro package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.
PyPICompromised package - resolvedcritical
Malicious code in ziugxfbvo (PyPI)
The PyPI package ziugxfbvo contained malicious code that executed automatically on import, functioning as an infostealer and remote access trojan (RAT) with capabilities including command execution, file exfiltration, screen recording, and GUI automation.
2026 04 Process SupportPyPICompromised package - resolvedcritical
Malicious code in zproxy2 (PyPI)
Malicious code was discovered in the zproxy2 package on PyPI. The package contained malicious code that could compromise systems installing it.
PyPICompromised package - resolvedcritical
Malicious code in ycodestyle (PyPI)
Malicious code was distributed in the ycodestyle package on PyPI as part of a campaign distributing 900+ malicious packages. The malicious packages infected local browsers with extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in zscaner (PyPI)
A coordinated malicious package campaign on PyPI targeting Telegram Desktop users. Five interdependent packages (zscaner, pyapiepo, reqinstall, zmaker, zsender) work together to locate, archive, and exfiltrate Telegram Desktop user data to a remote server.
PyPICompromised packageMalicious commit - resolvedcritical
Malicious code in zorosnitro (PyPI)
Malicious code was discovered in the zorosnitro package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.
PyPICompromised package - resolvedcritical
Malicious code in zlibxjson (PyPI)
Malicious code was published in the zlibxjson package on PyPI as part of the zlibxjson-discord-cookies campaign. The package contained infostealer functionality designed to steal Discord cookies and other sensitive data from infected systems.
Zlibxjson Discord CookiesPyPICompromised package - resolvedcritical
Malicious code in zproxy (PyPI)
Malicious code was discovered in the zproxy package on PyPI. The package contained malicious functionality and was identified by the OpenSSF malicious packages project.
PyPICompromised package - containedcritical
Malware in svelte-streaks
Malware was discovered in the npm package svelte-streaks, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malicious code in adpull (PyPI)
The adpull package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adram (PyPI)
The PyPI package adram contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adpep (PyPI)
The adpep package on PyPI contained malicious code as part of a campaign by EsqueleSquad group. The group published nearly 6,000 malicious PyPI and NPM packages designed to execute spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in aeodata (PyPI)
Malicious code was discovered in the aeodata package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in agents-kit (PyPI)
Malicious code was discovered in the agents-kit package on PyPI. The package was flagged by the OpenSSF malicious packages database as containing malicious code.
PyPIAI agents & skillsCompromised package - resolvedcritical
Malicious code in adultra (PyPI)
The adultra package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedhigh
Malicious code in ai-labs-snippets-sdk (PyPI)
The ai-labs-snippets-sdk package on PyPI contained malicious code that exfiltrates system information (IP address, username, .gitconfig) to a remote target. The malicious payload was embedded as pickle-serialized code within a file disguised as an AI model, executed during package import.
2025 05 AI Labs Snippets SdkPyPICompromised package - resolvedcritical
Malicious code in afritonpy (PyPI)
Malicious code was discovered in the afritonpy package on PyPI. The package contained intentional malicious functionality that could compromise systems installing it.
PyPICompromised package - resolvedhigh
Malicious code in accesspdp (PyPI)
The accesspdp package version 2.0.1 on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.
PyPICompromised package - resolvedcritical
Malicious code in 3m-promo-gen-api (PyPI)
Malicious code was discovered in the 3m-promo-gen-api package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.
PyPICompromised package - resolvedcritical
Malicious code in 191239aa (PyPI)
Malicious code was published in the PyPI package 191239aa. The package was identified and cataloged by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in 4123 (PyPI)
Malicious code was discovered in the PyPI package 4123. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4727.
PyPICompromised package - resolvedcritical
Malicious code in 233-misc (PyPI)
Malicious code was discovered in the 233-misc package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in 1923tsl1 (PyPI)
Malicious code was discovered in the 1923tsl1 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in 7-0 (PyPI)
Malicious code was discovered in the PyPI package 7-0. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.
PyPICompromised package - resolvedcritical
Malicious code in 3m-promo-link-gen (PyPI)
Malicious code was discovered in the 3m-promo-link-gen package on PyPI. The package was flagged by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4726.
PyPICompromised package - resolvedcritical
Malicious code in 90456984689490856 (PyPI)
Malicious code was published in the PyPI package 90456984689490856. The package was identified and cataloged by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in abhamzufu (PyPI)
The PyPI package abhamzufu contained malicious code that executed during installation via a compromised setup.py install command override. The package had no legitimate purpose and was part of the 2025-10-wangzhou183 campaign.
2025 10 Wangzhou183PyPICompromised package - resolvedcritical
Malicious code in aaiohttp (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including aaiohttp, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in account-eth (PyPI)
Malicious code was discovered in the account-eth package on PyPI. The package contained unauthorized code injected into one or more versions.
PyPICompromised package - resolvedcritical
Malicious code in aaaazzzzaz (PyPI)
The PyPI package aaaazzzzaz contained malicious code that downloads and executes a remote executable during installation. The package was part of the 2026-06-easyaillm campaign and has been identified and removed.
2026 06 EasyaillmPyPICompromised package - resolvedcritical
Malicious code in abilityrequests (PyPI)
Malicious code was discovered in the abilityrequests package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.
PyPICompromised package - resolvedcritical
Malicious code in acloud-client (PyPI)
A multi-year malicious campaign on PyPI distributed packages (acloud-client, time-check-server, snapshot-photo) that clone legitimate cloud SDK packages and exfiltrate cloud credentials to remote servers. The campaign used obfuscation techniques, hiding malicious functionality in dependency chains.
PyPICompromised packageMalicious commit - resolvedhigh
Malicious code in adafruit-display-text (PyPI)
Malicious code was published in the adafruit-display-text package on PyPI. The package exfiltrates basic host information (IP address, username) and executes malicious code during installation via setup.py override.
PyPICompromised package - containedcritical
Malicious code in acloud-clients (PyPI)
A multi-year malicious campaign on PyPI distributes packages that clone legitimate cloud SDK libraries (acloud-clients, AWS clients) and inject code to exfiltrate cloud credentials via hidden dependencies like time-check-server and snapshot-photo.
PyPICompromised packageMalicious commit - resolvedhigh
Malicious code in abseil-py (PyPI)
Malicious code was published in the abseil-py package on PyPI that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious code.
PyPICompromised package - resolvedcritical
Malicious code in acapy-agent-didx (PyPI)
Malicious code was discovered in the acapy-agent-didx package on PyPI. The package was identified by the OpenSSF malicious packages project as containing malicious code.
PyPICompromised package - resolvedhigh
Malicious code in adafruit-imageload (PyPI)
The adafruit-imageload package on PyPI contained malicious code that exfiltrated basic host information (IP address, username) during installation. The package overrode the install command in setup.py to execute the malicious payload.
PyPICompromised package - resolvedcritical
Malicious code in admask (PyPI)
The admask package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a coordinated campaign by the EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adhttp (PyPI)
The adhttp package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malware executed spyware and information-stealing functionality.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adm3 (PyPI)
Malicious code was discovered in the adm3 package on PyPI. The incident was identified and documented by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in adgui (PyPI)
The adgui package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedhigh
Malicious code in adent-core-api (PyPI)
The adent-core-api package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload when installed.
PyPICompromised package - resolvedcritical
Malicious code in adhydra (PyPI)
The adhydra package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adosint (PyPI)
The adosint package on PyPI was identified as malicious code, part of a campaign by EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM. The package executes spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adproof (PyPI)
The adproof package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adpyw (PyPI)
The PyPI package adpyw contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedhigh
Malicious code in adandv (PyPI)
The adandv package on PyPI contained malicious code designed to exfiltrate basic system information (hostname, path, username) to the package author. The package was part of a broader campaign of malicious pentest-themed packages flooding PyPI.
PyPICompromised packageTyposquattingDependency confusion - resolvedhigh
Malicious code in adandu (PyPI)
The PyPI package 'adandu' was identified as malicious, containing code to exfiltrate basic system information (hostname, path, username) upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages and communicated with domains associated with malicious activity.
PyPICompromised packageTyposquattingDependency confusion - resolvedcritical
Malicious code in admcheck2 (PyPI)
Malicious code was discovered in the admcheck2 package on PyPI. The package contained malicious code that could compromise systems installing it.
PyPICompromised package - resolvedcritical
Malicious code in adcontrol (PyPI)
The adcontrol package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in admc (PyPI)
The admc package on PyPI was identified as malicious, containing spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM ecosystems.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adcpu (PyPI)
The PyPI package adcpu contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adinfo (PyPI)
The adinfo package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adcv (PyPI)
The adcv package on PyPI contained malicious code as part of a campaign by the EsqueleSquad group. The group published nearly 6000 malicious PyPI and NPM packages designed to execute spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adpaypal (PyPI)
The adpaypal package on PyPI contained malicious code executing spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adminbypasser (PyPI)
Malicious code was published in the adminbypasser package on PyPI. The package silently downloads and executes remote code, establishing persistence via autostart mechanisms. The remote domain used by the malware no longer exists at the time of analysis.
PyPICompromised package - resolvedcritical
Malicious code in adv2099m2 (PyPI)
Malicious code was discovered in the adv2099m2 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in adv2099m6 (PyPI)
Malicious code was discovered in the adv2099m6 package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.
PyPICompromised package - resolvedcritical
Malicious code in ziphash (PyPI)
The ziphash package on PyPI contained malicious code that downloads and executes multi-stage malware during archive-support class initialization. The malware exhibits obfuscation and remote code execution capabilities, classified as part of the 2025-11-uzip campaign.
2025 11 UzipPyPICompromised package - resolvedcritical
Malicious code in adrandom (PyPI)
The adrandom package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adv2099m7 (PyPI)
Malicious code was discovered in the adv2099m7 package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in afrit-name (PyPI)
Malicious code was discovered in the afrit-name package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in adstr (PyPI)
The adstr package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in afriton-py (PyPI)
Malicious code was discovered in the afriton-py package on PyPI. The package contained intentionally injected malicious code that could compromise systems installing it.
PyPICompromised package - resolvedcritical
Malicious code in agent-user-generate (PyPI)
The PyPI package agent-user-generate contained malicious code that exfiltrated user data, downloaded and executed next-stage payloads, and installed infostealer malware (Lumma and a custom variant). The package cloned a legitimate project and hid malicious functionality within library usage.
PyPICompromised package - resolvedcritical
Malicious code in aeodatav04 (PyPI)
Malicious code was discovered in the aeodatav04 package on PyPI. The package contained malicious functionality and was identified by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in advm (PyPI)
The advm package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedhigh
Malicious code in advdef01 (PyPI)
The PyPI package advdef01 contained malicious code designed to exfiltrate system information (IP address, username) during installation. The package used a setup.py override to execute the malicious payload when installed.
PyPICompromised packageMalicious commit - resolvedcritical
Malicious code in adurl (PyPI)
The adurl package on PyPI was identified as malicious, containing spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedhigh
Malicious code in affinequant (PyPI)
The affinequant package on PyPI contained malicious code that exfiltrated basic system information (hostname, path, username) to the package author upon installation or import. The package was part of a broader campaign of malicious packages on PyPI and communicated with a domain associated with malicious activity.
PyPICompromised packageTyposquattingDependency confusion - resolvedcritical
Malicious code in adv2099m5 (PyPI)
Malicious code was discovered in the adv2099m5 package on PyPI. The package contained intentional malicious functionality and has been cataloged by the OpenSSF malicious packages database.
PyPICompromised package - activecritical
Malware in chai-as-reddit
Malware discovered in the npm package chai-as-reddit. Systems with this package installed are considered fully compromised and may have given outside entities full control.
npmCompromised package - activecritical
Malware in chai-leaf
Malware discovered in the npm package chai-leaf. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - containedcritical
Malware in streak-calendar
Malware was discovered in the npm package streak-calendar. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in streak-daycount
Malware was discovered in the npm package streak-daycount. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malicious code in yfinanec (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinanec, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in yelp-pkg (PyPI)
yelp-pkg, a malicious package on PyPI, was designed to exfiltrate sensitive data including environment variables during installation. The package overrides the install command in setup.py to execute malicious code and appears to be a typosquatting attack.
PyPICompromised packageTyposquatting - resolvedhigh
Malicious code in xx-ent-wiki-sm (PyPI)
The PyPI package xx-ent-wiki-sm contained malicious code that exfiltrates basic host information (IP, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.
PyPICompromised package - resolvedcritical
Malicious code in xwormclient (PyPI)
The xwormclient package on PyPI contained malicious code that downloads and executes a remote executable upon import. The package was identified as part of campaign 2025-08-k7eel and has been flagged by the OpenSSF malicious packages database.
2025 08 K7eelPyPICompromised package - resolvedcritical
Malicious code in yellorq (PyPI)
Malicious code was discovered in the yellorq package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing intentional malicious functionality.
PyPICompromised package - resolvedcritical
Malicious code in xuiniadb (PyPI)
Malicious code was discovered in the xuiniadb package on PyPI. The package contained malicious code that could compromise systems installing it.
PyPICompromised package - resolvedcritical
Malicious code in yfiance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfiance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in ysocks (PyPI)
Malicious code was distributed in the ysocks package on PyPI as part of a campaign distributing 900+ malicious packages. The malicious packages installed browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in ypj (PyPI)
Malicious code was discovered in the ypj package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.
PyPICompromised package - resolvedcritical
Malicious code in ypinstaller (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including ypinstaller, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in ytest-cov (PyPI)
Malicious code was discovered in the ytest-cov package on PyPI. The package contained malicious payload that could compromise systems of users who installed it.
PyPICompromised package - containedcritical
Malicious code in yt-api-dlp (PyPI)
yt-api-dlp, a typosquat of the legitimate yt-dlp package on PyPI, contains malicious code that downloads encrypted payloads and communicates with a C2 server via the Polygon blockchain during import. The package was a near-verbatim copy of yt-dlp with added malicious functionality.
PyPITyposquattingCompromised package - resolvedcritical
Malicious code in youtubebot (PyPI)
Malicious code was discovered in the youtubebot package on PyPI. The package was flagged by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6251.
PyPICompromised package - resolvedcritical
Malicious code in ypthon-binance (PyPI)
Over 900 malicious packages were distributed via PyPI, including ypthon-binance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised packageTyposquatting - resolvedhigh
Malicious code in zabitog (PyPI)
Malicious code was discovered in the zabitog package on PyPI. The package contained obfuscated code designed to exfiltrate basic system data such as hostname, IP address, and username. The incident was identified as part of campaign 2026-02-zabitmajeed00 and attributed to OpenSSF's malicious packages research.
PyPICompromised packageDependency confusion - resolvedcritical
Malicious code in zakuraweb (PyPI)
The zakuraweb package on PyPI contained malicious code that exfiltrates Discord tokens upon import. The package was identified as part of the 2025-11-morosint campaign and has been documented by the OpenSSF malicious packages repository.
2025 11 MorosintPyPICompromised package - resolvedcritical
Malicious code in zeubilamouche (PyPI)
Malicious code was discovered in the zeubilamouche package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in zlib1g-dev (PyPI)
Malicious code was discovered in the zlib1g-dev package on PyPI. The package was identified by the OpenSSF malicious packages project as containing malicious code.
PyPICompromised package - resolvedhigh
Malicious code in zero123 (PyPI)
Malicious code was published in the zero123 package on PyPI as part of a pentest campaign. The package exfiltrates basic system information (hostname, path, username) to the package author upon installation or import.
PyPICompromised packageTyposquatting - containedcritical
Malware in @apexfdn/apex
The npm package @apexfdn/apex was found to contain malware, potentially giving full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malicious code in zzzzthisisitwantsafecheckitzzzz (PyPI)
The PyPI package zzzzthisisitwantsafecheckitzzzz version 1.0.0 contained malicious code that downloads and executes remote backdoor trojans during installation when run under specific usernames. The OpenSSF Package Analysis project confirmed the package executes commands associated with malicious behavior.
PyPICompromised package - resolvedcritical
Malicious code in zenomenallib (PyPI)
zenomenallib, a PyPI package, contained malicious code designed to exfiltrate sensitive files. The malicious payload was embedded in different locations across variants: module import, native binaries, or setup.py scripts. The package was identified and cataloged as part of the 2025-08-xenlib campaign.
2025 08 XenlibPyPICompromised package - resolvedcritical
Malicious code in zlsrc (PyPI)
Malicious code was discovered in the zlsrc package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-6626.
PyPICompromised package - resolvedcritical
Malicious code in zmaker (PyPI)
A coordinated malicious package campaign on PyPI targeted Telegram Desktop users. Five interdependent packages (zmaker, zscaner, pyapiepo, reqinstall, zsender) worked together to locate, archive, and exfiltrate Telegram user data to a remote server.
PyPICompromised packageMalicious commit - resolvedcritical
Malicious code in 3web-py (PyPI)
The PyPI package 3web-py contained malicious code designed to function as an infostealer. The package was part of the funcaptcha-ru campaign and has been identified and cataloged by the OpenSSF malicious packages project.
Funcaptcha RU CampaignPyPICompromised package - resolvedcritical
Malicious code in 3-0 (PyPI)
Malicious code was discovered in the 3-0 package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.
PyPICompromised package - resolvedcritical
Malicious code in 3web (PyPI)
The PyPI package 3web contained malicious code designed to steal information. The package was part of the funcaptcha-ru campaign and has been identified and cataloged by the OpenSSF malicious packages project.
Funcaptcha RUPyPICompromised package - resolvedcritical
Malicious code in 7miners (PyPI)
The 7miners package on PyPI contained malicious code designed to clone legitimate libraries with modifications. The package downloads and executes arbitrary remote code via Telegram as a command-and-control channel.
2026 03 PipipipiPyPICompromised packageTyposquatting - resolvedcritical
Malicious code in adad (PyPI)
The PyPI package 'adad' contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in aclient-sdk (PyPI)
aclient-sdk on PyPI contains malicious code designed to exfiltrate cloud credentials. The package is a clone of the legitimate aliyun-python-sdk-core with injected code that imports a credential-stealing dependency and exfiltrates AWS/Alibaba Cloud tokens to a remote server.
PyPICompromised packageMalicious commit - resolvedcritical
Malicious code in a1rn (PyPI)
Malicious code was discovered in the a1rn package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4729.
PyPICompromised package - resolvedcritical
Malicious code in a3s-code (PyPI)
The a3s-code PyPI package contained malicious code that fetched and executed native binaries (.so/.pyd/.dylib) from a GitHub organization (A3S-Lab) distinct from the documented project (AI45Lab), bypassing pip build isolation and hash verification.
PyPICompromised packageTyposquatting - resolvedhigh
Malicious code in acpi-tables (PyPI)
The acpi-tables package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload when installed.
PyPICompromised package - resolvedhigh
Malicious code in adanbu (PyPI)
The PyPI package 'adanbu' version 92.6 contained malicious code that exfiltrated basic system information (hostname, path, username) to the package author upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages on PyPI.
PyPICompromised packageTyposquattingDependency confusion - resolvedcritical
Malicious code in acloud-client-uses (PyPI)
A malicious PyPI package named acloud-client-uses was discovered as part of a multi-year campaign that clones legitimate cloud SDK packages and exfiltrates credentials. The package imports a helper module (time-check-server) that sends cloud credentials to a remote server instead of benign data.
PyPICompromised packageTyposquatting - resolvedcritical
Malicious code in adgame (PyPI)
The adgame package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adload (PyPI)
The adload package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adgrand (PyPI)
The adgrand package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM ecosystems. The malicious code executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adpost (PyPI)
The adpost package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adm4 (PyPI)
Malicious code was discovered in the adm4 package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in adcandy (PyPI)
The adcandy package on PyPI contained malicious code designed to execute spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - containedcritical
Malicious code in zakuchienne (PyPI)
The PyPI package zakuchienne contains malicious code that functions as an infostealer, exfiltrating credentials, browser data, and files. The malware includes sandbox detection capabilities and was identified as part of the 2025-11-mescouilles campaign.
2025 11 MescouillesPyPICompromised package - resolvedhigh
Malicious code in aet-test (PyPI)
The aet-test package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.
PyPICompromised package - resolvedcritical
Malicious code in advirtual (PyPI)
The advirtual package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adcraft (PyPI)
The adcraft package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in znomig (PyPI)
Malicious code was discovered in the znomig package on PyPI. The package contained intentional malicious functionality and was cataloged by the OpenSSF malicious packages database.
PyPICompromised package - resolvedcritical
Malicious code in admcheck (PyPI)
Malicious code was discovered in multiple versions of the admcheck package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.
PyPICompromised package - resolvedcritical
Malicious code in adv2099m (PyPI)
Malicious code was discovered in the adv2099m package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4734.
PyPICompromised package - resolvedcritical
Malicious code in adv2099m4 (PyPI)
Malicious code was discovered in the adv2099m4 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in adtool (PyPI)
The adtool package on PyPI contained malicious code that executed spyware and information-stealing malware. This package was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adpip (PyPI)
The adpip package on PyPI was identified as malicious code, part of a campaign by EsqueleSquad that published nearly 6000 malicious packages across PyPI and NPM. The package executes spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in xoloxwmellxliq (PyPI)
Malicious code was discovered in the xoloxwmellxliq package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6248.
PyPICompromised package - resolvedcritical
Malicious code in xologrekjlqzxj (PyPI)
Malicious code was discovered in the xologrekjlqzxj package on PyPI. The package was identified and reported by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in xoloqmotdjpbic (PyPI)
Malicious code was discovered in the xoloqmotdjpbic package on PyPI. The package was identified and reported by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in zipf (PyPI)
Malicious code was discovered in the zipf package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.
PyPICompromised package - resolvedcritical
Malicious code in 1q847 (PyPI)
The PyPI package 1q847 contained malicious code in the form of two DLL libraries, one of which was packed. Both libraries were recognized as malware with infosteal capabilities. The package was identified and cataloged as part of the OpenSSF malicious packages campaign.
PyPICompromised package - resolvedhigh
Malicious code in xsltproc (PyPI)
The xsltproc package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) upon installation or module import. The package overrides the install command in setup.py to execute the malicious payload during installation.
PyPICompromised package - resolvedcritical
Malicious code in zsender (PyPI)
A coordinated malicious package campaign on PyPI consisting of five interdependent packages (zsender, zscaner, pyapiepo, reqinstall, zmaker) designed to steal Telegram Desktop user data. The packages work together to locate Telegram Desktop folders, archive user data, and exfiltrate it to a remote server.
PyPICompromised packageMalicious commit - resolvedcritical
Malicious code in zking (PyPI)
Malicious code was discovered in the zking package on PyPI. The package contained malicious code that could compromise systems installing it.
PyPICompromised package - resolvedcritical
Malicious code in afriton (PyPI)
Malicious code was discovered in the afriton package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-11514.
PyPICompromised package - resolvedcritical
Malicious code in 48484efej8id (PyPI)
Malicious code was published in the PyPI package 48484efej8id. The package was identified and cataloged by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in zebo (PyPI)
The zebo package on PyPI contained malicious code that automatically installs a keylogger and screenshot extraction tool with autostart persistence. The malicious campaign was identified and attributed to OpenSSF's malicious packages database.
PyPICompromised package - containedcritical
Malicious code in youreallydontwantthispackage2131 (PyPI)
Malicious package youreallydontwantthispackage2131 version 1.0.1 published to PyPI with code designed to exfiltrate GCP tokens. The OpenSSF Package Analysis project and security researcher kam193 identified the package communicating with malicious domains and executing suspicious commands.
PyPICompromised package - resolvedcritical
Malicious code in a-oder (PyPI)
Malicious code was published in the a-oder package on PyPI as part of the 2024-07-weaponized-golden campaign. The malware was designed for file exfiltration. The package has been identified and documented by the OpenSSF malicious-packages project.
2024 07 Weaponized GoldenPyPICompromised package - resolvedcritical
Malicious code in ztasimb (PyPI)
Malicious code was discovered in the ztasimb package on PyPI. The package was identified and reported by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in zydnitro (PyPI)
Malicious code was discovered in the zydnitro package on PyPI. The package contained malicious functionality and was identified by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in ygame (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including ygame, containing code that infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-busl-1-1
The npm package @gocortexio/npmgremlinbox-busl-1-1 contains malware that grants full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-cern-ohl-s-2-0
The npm package @gocortexio/npmgremlinbox-cern-ohl-s-2-0 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-cc-by-sa-2-0-uk
The npm package @gocortexio/npmgremlinbox-cc-by-sa-2-0-uk contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - containedcritical
Malware in upjsma
The npm package upjsma was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malicious code in OCI.DotNetSDK.Osubusage.Net (NuGet)
Malicious code was discovered in the OCI.DotNetSDK.Osubusage.Net NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-6hmv-h8cf-m32h.
NuGetCompromised package - resolvedcritical
Malicious code in OCI.DotNetSDK.Threat.intelligence (NuGet)
Malicious code was discovered in the OCI.DotNetSDK.Threat.intelligence NuGet package. The incident was identified and reported via the OpenSSF malicious packages database.
NuGetCompromised package - resolvedcritical
Malicious code in Reddit.api (NuGet)
Malicious code was discovered in multiple versions of the Reddit.api NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Rimworld.Reference.Libary (NuGet)
Malicious code was discovered in multiple versions of the Rimworld.Reference.Libary NuGet package. The package was compromised and distributed via the NuGet package registry.
NuGetCompromised package - resolvedcritical
Malicious code in seedefender (NuGet)
Malicious code was discovered in the seedefender NuGet package. The incident was identified and reported via the OpenSSF malicious packages database.
NuGetCompromised package - resolvedcritical
Malicious code in Sanka.UI.WinForms (NuGet)
Malicious code was discovered in multiple versions of the Sanka.UI.WinForms NuGet package. The vulnerability was identified and reported through the OpenSSF malicious packages database.
NuGetCompromised package - resolvedcritical
Malicious code in Sanka.UI2.WinForms (NuGet)
Malicious code was discovered in multiple versions of the Sanka.UI2.WinForms NuGet package. The package was identified by the OpenSSF malicious-packages project as containing malicious code.
NuGetCompromised package - resolvedcritical
Malicious code in Rimworld.References.Net (NuGet)
Malicious code was discovered in multiple versions of the Rimworld.References.Net NuGet package. The package was compromised and distributed through the NuGet package registry.
NuGetCompromised package - resolvedcritical
Malicious code in SharpCashAddr.Core (NuGet)
Malicious code was discovered in SharpCashAddr.Core NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in solnetunified (NuGet)
Malicious code was discovered in the solnetunified NuGet package. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-191615.
NuGetCompromised package - resolvedcritical
Malicious code in Sanka.UI3.WinForms (NuGet)
Multiple versions of the Sanka.UI3.WinForms NuGet package contained malicious code. The incident was identified and credited to the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in solnetall.net (NuGet)
Malicious code was discovered in the solnetall.net NuGet package. The package was identified by the OpenSSF malicious packages project and cataloged as MAL-2026-1887.
NuGetCompromised package - resolvedcritical
Malicious code in solnetall (NuGet)
Malicious code was discovered in multiple versions of the solnetall NuGet package. The vulnerability was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Stl.Generators.Net (NuGet)
Malicious code was discovered in the Stl.Generators.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Stl.Fusion.Ext.Contracts.Net (NuGet)
Malicious code was discovered in the Stl.Fusion.Ext.Contracts.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Stl.Fusion.Ext.Services.Net (NuGet)
Malicious code was discovered in the Stl.Fusion.Ext.Services.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Stl.Rpc.Server.Net.Fx (NuGet)
Malicious code was discovered in the Stl.Rpc.Server.Net.Fx NuGet package. The package was identified by the OpenSSF malicious-packages project as containing malicious code (MAL-2024-4663).
NuGetCompromised package - resolvedcritical
Malicious code in solnetplus (NuGet)
Malicious code was discovered in multiple versions of the solnetplus NuGet package. The incident was identified and reported by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Shade.UI.WinForms (NuGet)
Malicious code was discovered in multiple versions of the Shade.UI.WinForms NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Tessa.Postgre.Sql (NuGet)
Malicious code was discovered in the Tessa.Postgre.Sql NuGet package. The incident was identified and reported by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Syntellect.Winium.Element (NuGet)
Malicious code was discovered in the Syntellect.Winium.Element NuGet package. The package was identified by the OpenSSF malicious-packages project as containing malicious code.
NuGetCompromised package - resolvedcritical
Malicious code in Tessa.Core (NuGet)
Malicious code was discovered in the Tessa.Core NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in OtpCsharp (NuGet)
Malicious code was discovered in multiple versions of the OtpCsharp NuGet package. The incident was documented by the OpenSSF malicious packages project and published as advisory GHSA-5xcp-2vmr-7f23.
NuGetCompromised package - resolvedcritical
Malicious code in Tessa.Analyzer (NuGet)
Malicious code was discovered in the Tessa.Analyzer NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Tessa.Windows.V2 (NuGet)
Malicious code was discovered in the Tessa.Windows.V2 NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-vgqj-xf7p-6mh4.
NuGetCompromised package - resolvedcritical
Malicious code in WpfLightToolkit.Net (NuGet)
Malicious code was discovered in the WpfLightToolkit.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in WindowsAPICodePack.Net (NuGet)
Malicious code was discovered in the WindowsAPICodePack.Net NuGet package. The OpenSSF malicious packages project identified and documented the incident as MAL-2024-4695.
NuGetCompromised package - resolvedcritical
Malicious code in test6789.latest (NuGet)
Malicious code was discovered in the test6789.latest NuGet package. The package was identified and cataloged by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Whatsapp.API (NuGet)
Malicious code was discovered in multiple versions of the Whatsapp.API NuGet package. The package was compromised and distributed through the NuGet package registry.
NuGetCompromised package - resolvedcritical
Malicious code in Shade.WPF.Controls (NuGet)
Multiple versions of the Shade.WPF.Controls NuGet package contained malicious code. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in testt22esttest (NuGet)
Malicious code was discovered in the testt22esttest NuGet package. The package was identified and reported by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Wpf.UI.WinForms (NuGet)
Malicious code was discovered in the Wpf.UI.WinForms NuGet package. The incident was identified and reported by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in xopxopxopxopxopx (NuGet)
Malicious code was discovered in the xopxopxopxopxopx NuGet package. The package was identified and reported by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Xam.Plugins.Forms.Svg.Net (NuGet)
Malicious code was discovered in the Xam.Plugins.Forms.Svg.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Zendesk.Drivers (NuGet)
Malicious code was discovered in the Zendesk.Drivers NuGet package. The OpenSSF malicious packages project identified and documented the incident under MAL-2024-4710.
NuGetCompromised package - resolvedcritical
Malicious code in WpfScreenHelper.Net (NuGet)
Malicious code was discovered in the WpfScreenHelper.Net NuGet package. The package was compromised and distributed with malicious payload. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Zendesk.Client (NuGet)
Malicious code was discovered in the Zendesk.Client NuGet package. The OpenSSF malicious packages project identified and documented the incident under MAL-2024-4709.
NuGetCompromised package - resolvedcritical
Malicious code in stripeapi.net (NuGet)
Malicious code was discovered in multiple versions of the stripeapi.net NuGet package. The incident was identified and documented by the OpenSSF malicious-packages project.
NuGetCompromised package - resolvedcritical
Malicious code in PubIishIgnore (NuGet)
Malicious code was discovered in the PubIishIgnore NuGet package. The package contained intentional malicious functionality and was flagged by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Reactive.GUI.Winforms (NuGet)
Malicious code was discovered in the Reactive.GUI.Winforms NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-45h9-gh73-7ghq.
NuGetCompromised package - resolvedcritical
Malicious code in wpfuihelpercore (NuGet)
Malicious code was discovered in the wpfuihelpercore NuGet package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-2808.
NuGetCompromised package - containedcritical
Malware in alb-lambda-cdk
Malware was discovered in the npm package alb-lambda-cdk. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malicious code in Zendesk-Api (NuGet)
Malicious code was discovered in multiple versions of the Zendesk-Api NuGet package. The incident was identified and documented by the OpenSSF malicious-packages project (MAL-2024-4708).
NuGetCompromised package - containedcritical
Malware in lwc-slds-lbc
Malware was discovered in the npm package lwc-slds-lbc, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in s3-lambda-dynamodb-cdk
Malware was discovered in the npm package s3-lambda-dynamodb-cdk. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.
npmCompromised package - containedcritical
Malware in lambda-cloudwatch-cdk
Malware was discovered in the npm package lambda-cloudwatch-cdk. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.
npmCompromised package - activecritical
Malware in iot-kfh-s3
The npm package iot-kfh-s3 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malicious code in psbuiId (NuGet)
Malicious code was discovered in the psbuiId NuGet package. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4618.
NuGetCompromised package - resolvedcritical
Malicious code in PDFTron.NETCore.Windows.x64.Net (NuGet)
Malicious code was discovered in PDFTron.NETCore.Windows.x64.Net NuGet package. The package was identified by the OpenSSF malicious packages project and cataloged as MAL-2024-4613.
NuGetCompromised package - resolvedcritical
Malicious code in Pathoschild.Stardew.ModBuildConfig.Net (NuGet)
Malicious code was discovered in multiple versions of the Pathoschild.Stardew.ModBuildConfig.Net NuGet package. The package was compromised and distributed via the NuGet package registry, affecting developers who depend on it for Stardew Valley mod development.
NuGetCompromised package - resolvedcritical
Malicious code in OCI.DotNetSDK.Servicemanager.proxy (NuGet)
Malicious code was discovered in the NuGet package OCI.DotNetSDK.Servicemanager.proxy. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4597. The incident was publicly disclosed on July 20, 2026.
NuGetCompromised package - resolvedcritical
Malicious code in Rockstar.AssetManager.Infrastructure (NuGet)
Malicious code was discovered in the Rockstar.AssetManager.Infrastructure NuGet package. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Advisory GHSA-j328-7g3v-fw47.
NuGetCompromised package - resolvedcritical
Malicious code in Resource.Embedder.Net (NuGet)
Malicious code was discovered in the Resource.Embedder.Net NuGet package. The package was identified by the OpenSSF malicious packages project as containing malicious code.
NuGetCompromised package - resolvedcritical
Malicious code in Ripple.NetCore.Api (NuGet)
Malicious code was discovered in the Ripple.NetCore.Api NuGet package. The OpenSSF malicious packages project identified and documented the compromise under identifier MAL-2024-4631.
NuGetCompromised package - resolvedcritical
Malicious code in Reothor.Lab.EvilPackage (NuGet)
Malicious code was discovered in multiple versions of the Reothor.Lab.EvilPackage NuGet package. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4626.
NuGetCompromised package - resolvedcritical
Malicious code in RSG.Base (NuGet)
Malicious code was discovered in the RSG.Base NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in PayPalMerchant.SDK (NuGet)
Malicious code was discovered in multiple versions of the PayPalMerchant.SDK NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in security_hacks (NuGet)
Malicious code was discovered in the security_hacks NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-348g-27q2-qxc6.
NuGetCompromised package - resolvedcritical
Malicious code in ppy.osu.Game.Lib (NuGet)
Malicious code was discovered in multiple versions of the ppy.osu.Game.Lib NuGet package. The vulnerability was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Simplify.Windows.Forms.Net (NuGet)
Malicious code was discovered in the Simplify.Windows.Forms.Net NuGet package. The OpenSSF malicious packages project identified and documented the compromise under identifier MAL-2024-4642.
NuGetCompromised package - resolvedcritical
Malicious code in SolanaWallet (NuGet)
Malicious code was discovered in the SolanaWallet NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Solana (NuGet)
Malicious code was discovered in multiple versions of the Solana NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Skylark.Net (NuGet)
Malicious code was discovered in the Skylark.Net NuGet package. The compromise was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in sharpdefender (NuGet)
Malicious code was discovered in the sharpdefender NuGet package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2025-2924.
NuGetCompromised package - resolvedcritical
Malicious code in sqzrframework480 (NuGet)
Malicious code was discovered in the sqzrframework480 NuGet package. The package contained intentional malicious functionality and was published to the NuGet registry.
NuGetCompromised package - resolvedcritical
Malicious code in Stl.Plugins.Extensions.Net (NuGet)
Malicious code was discovered in the Stl.Plugins.Extensions.Net NuGet package. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4660.
NuGetCompromised package - resolvedcritical
Malicious code in Stl.RestEase.Net (NuGet)
Malicious code was discovered in the Stl.RestEase.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Stl.CommandLine.Net (NuGet)
Malicious code was discovered in the Stl.CommandLine.Net NuGet package. The OpenSSF malicious packages project identified and documented the incident.
NuGetCompromised package - resolvedcritical
Malicious code in Soenneker.Redis.Util.Net (NuGet)
Malicious code was discovered in multiple versions of the Soenneker.Redis.Util.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Tessa.Web.Client.Net (NuGet)
Malicious code was discovered in the Tessa.Web.Client.Net NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-qqc8-8f3p-cq7w.
NuGetCompromised package - resolvedcritical
Malicious code in Superpower-Api (NuGet)
Malicious code was discovered in the Superpower-Api NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Syntellect.Winium.Cruciatus.Net (NuGet)
Malicious code was discovered in the NuGet package Syntellect.Winium.Cruciatus.Net. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-6xrh-c8f5-qg9f.
NuGetCompromised package - resolvedcritical
Malicious code in Tessa.Server.Net (NuGet)
Malicious code was discovered in the Tessa.Server.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in solnetwallet.net.core (NuGet)
Malicious code was discovered in multiple versions of the solnetwallet.net.core NuGet package. The package was identified by the OpenSSF malicious packages project and published as advisory GHSA-v3mq-96fv-mggm on July 20, 2026.
NuGetCompromised package - resolvedcritical
Malicious code in Tessa.UI2 (NuGet)
Malicious code was discovered in the Tessa.UI2 NuGet package. The package was identified and cataloged by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Syntellect.Winium.Web.Driver (NuGet)
Malicious code was discovered in the Syntellect.Winium.Web.Driver NuGet package. The package was flagged by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4668.
NuGetCompromised package - resolvedcritical
Malicious code in Tessa.Compilations (NuGet)
Malicious code was discovered in the Tessa.Compilations NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Tessa.Net.V2 (NuGet)
Malicious code was discovered in the Tessa.Net.V2 NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-hjvp-gm48-34mp.
NuGetCompromised package - resolvedcritical
Malicious code in Tessa.Linux.V2 (NuGet)
Malicious code was discovered in the Tessa.Linux.V2 NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-447h-gf6j-f83q.
NuGetCompromised package - resolvedcritical
Malicious code in vspropertypages (NuGet)
Malicious code was discovered in the vspropertypages NuGet package. The OpenSSF identified and documented the malicious package as part of their malicious-packages repository.
NuGetCompromised package - resolvedcritical
Malicious code in WpfAnimatedGif.Net (NuGet)
Malicious code was discovered in multiple versions of the WpfAnimatedGif.Net NuGet package. The compromise was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in WPF-UI-Net (NuGet)
Malicious code was discovered in the WPF-UI-Net NuGet package. The vulnerability was identified and reported via the OpenSSF malicious packages database.
NuGetCompromised package - resolvedcritical
Malicious code in UI2.Guna.Winforms (NuGet)
Malicious code was discovered in multiple versions of the UI2.Guna.Winforms NuGet package. The OpenSSF identified and documented the malicious package as part of their malicious packages database.
NuGetCompromised package - resolvedcritical
Malicious code in Rg.Plugins.Popups.Net (NuGet)
Malicious code was discovered in multiple versions of the Rg.Plugins.Popups.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project (MAL-2024-4628).
NuGetCompromised package - resolvedcritical
Malicious code in test6789.client (NuGet)
Malicious code was discovered in the test6789.client NuGet package. The package was identified and cataloged by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in test6789.v3 (NuGet)
Malicious code was discovered in test6789.v3 NuGet package. The package was identified and reported by the OpenSSF malicious-packages project.
NuGetCompromised package - resolvedcritical
Malicious code in TheOpenAI.API (NuGet)
Malicious code was discovered in multiple versions of the TheOpenAI.API NuGet package. The compromise was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Zendesk (NuGet)
Malicious code was discovered in the Zendesk NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-cc-by-sa-3-0-at
Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-sa-3-0-at. Installation of this package results in full system compromise, requiring immediate rotation of all secrets and keys from a separate computer.
npmCompromised package - resolvedcritical
Malicious code in XboxGamebar (NuGet)
Malicious code was discovered in the XboxGamebar NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in WPFMediaKit.Net (NuGet)
Malicious code was discovered in the WPFMediaKit.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Winforms (NuGet)
Malicious code was discovered in multiple versions of the Winforms package on NuGet. The incident was documented by the OpenSSF malicious packages project and published as GitHub advisory GHSA-wq82-5xjm-57wq.
NuGetCompromised package - resolvedcritical
Malicious code in Zendesk.OAuth (NuGet)
Malicious code was discovered in multiple versions of the Zendesk.OAuth NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in YoutubeExtractor.Net (NuGet)
Malicious code was discovered in the YoutubeExtractor.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Ultimate.Wpf.Toolkit (NuGet)
Multiple versions of the Ultimate.Wpf.Toolkit NuGet package contained malicious code. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-hippocratic-2-1
The npm package @gocortexio/npmgremlinbox-hippocratic-2-1 contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in svgson-lite
Malware was discovered in the npm package svgson-lite, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in express-ini
Malware discovered in the npm package express-ini. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.
npmCompromised package - activecritical
Malware in @car_loans/dealerships-approval
Malware discovered in the npm package @car_loans/dealerships-approval. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-agpl-1-0
Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-1-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-agpl-1-0-or-later
Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-1-0-or-later. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-agpl-3-0-only
Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-3-0-only. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-agpl-3-0-or-later
Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-3-0-or-later. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-cal-1-0-combined-work-exception
Malware was distributed via the npm package @gocortexio/npmgremlinbox-cal-1-0-combined-work-exception, providing full system compromise to any computer with the package installed or running.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-de
The npm package @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-de contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-de
The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-de contained malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-cc-by-sa-2-1-jp
The npm package @gocortexio/npmgremlinbox-cc-by-sa-2-1-jp contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-cddl-1-0
Malware was discovered in the npm package @gocortexio/npmgremlinbox-cddl-1-0. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-eupl-1-2
The npm package @gocortexio/npmgremlinbox-eupl-1-2 contained malware that grants full system compromise to attackers. All affected systems should be considered fully compromised and all secrets rotated immediately.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-gpl-2-0
Malware was discovered in the npm package @gocortexio/npmgremlinbox-gpl-2-0. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-cern-ohl-w-2-0
The npm package @gocortexio/npmgremlinbox-cern-ohl-w-2-0 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-sendmail-8-23
Malware discovered in npm package @gocortexio/npmgremlinbox-sendmail-8-23. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-c-uda-1-0
The npm package @gocortexio/npmgremlinbox-c-uda-1-0 contains malware that grants full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-typosquat-react
Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-react, a typosquatting attack. Systems with this package installed are considered fully compromised and require immediate remediation.
npmTyposquattingCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-tpl-1-0
Malware was distributed via the npm package @gocortexio/npmgremlinbox-tpl-1-0. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-typosquat-commander
A malicious npm package @gocortexio/npmgremlinbox-typosquat-commander was published, likely as a typosquatting attack. The package grants full system compromise to attackers.
npmTyposquattingCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-qpl-1-0-inria-2004
Malware was distributed via the npm package @gocortexio/npmgremlinbox-qpl-1-0-inria-2004. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-copyleft-next-0-3-0
The npm package @gocortexio/npmgremlinbox-copyleft-next-0-3-0 contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-ecos-2-0
The npm package @gocortexio/npmgremlinbox-ecos-2-0 contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-ncgl-uk-2-0
Malware was discovered in the npm package @gocortexio/npmgremlinbox-ncgl-uk-2-0. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @gocortexio/npmgremlinbox-wxwindows
Malware discovered in the npm package @gocortexio/npmgremlinbox-wxwindows. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-ucl-1-0
The npm package @gocortexio/npmgremlinbox-ucl-1-0 contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-unlicense
The npm package @gocortexio/npmgremlinbox-unlicense contained malware that provided full system compromise to attackers. Systems with this package installed should be considered fully compromised and all credentials rotated from a clean machine.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-copyleft-next-0-3-1
Malware was discovered in npm package @gocortexio/npmgremlinbox-copyleft-next version 0-3-1. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-tapr-ohl-1-0
Malware was distributed via the npm package @gocortexio/npmgremlinbox-tapr-ohl-1-0. Installation of this package results in full system compromise with potential for persistent malicious software.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-malware-c2-beacon
A malicious npm package @gocortexio/npmgremlinbox-malware-c2-beacon was published, containing a C2 beacon that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-malware-code-obfuscation
Malware was distributed via the npm package @gocortexio/npmgremlinbox-malware-code-obfuscation. Installation results in full system compromise with potential for persistent backdoor access.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-typosquat-express
Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-express, a typosquatting attack. Systems with this package installed should be considered fully compromised.
npmTyposquattingCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-malware-cryptomining-indicators
The npm package @gocortexio/npmgremlinbox-malware-cryptomining-indicators contained malware with cryptomining capabilities. Installation resulted in full system compromise, requiring immediate secret rotation and package removal.
npmCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-typosquat-lodash
Malware was distributed via the npm package @gocortexio/npmgremlinbox-typosquat-lodash, a typosquat of lodash. Installation grants full system compromise and requires immediate remediation including credential rotation and package removal.
npmTyposquattingCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-malware-credential-harvesting
The npm package @gocortexio/npmgremlinbox-malware-credential-harvesting contains malware capable of credential harvesting. Systems with this package installed should be considered fully compromised and all secrets rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-lgpl-2-0
Malware was discovered in the npm package @gocortexio/npmgremlinbox-lgpl-2-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-jpl-image
The npm package @gocortexio/npmgremlinbox-jpl-image contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-fdk-aac
Malware was discovered in the npm package @gocortexio/npmgremlinbox-fdk-aac. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-gpl-3-0
Malware was discovered in the npm package @gocortexio/npmgremlinbox-gpl-3-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-lgpl-3-0
The npm package @gocortexio/npmgremlinbox-lgpl-3-0 contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in vybscan-testbed-obfuscated-postinstall
The npm package vybscan-testbed-obfuscated-postinstall contains malware that grants full system compromise to an outside entity. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - resolvedcritical
Malware in vybscan-testbed-inert-postinstall
Malware was distributed via the npm package vybscan-testbed-inert-postinstall. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in next-locomotive-init
The npm package next-locomotive-init was found to contain malware. Installation or execution of this package results in full system compromise. All affected systems should be considered fully compromised and all secrets and keys rotated from a clean machine.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-cpol-1-02
The npm package @gocortexio/npmgremlinbox-cpol-1-02 contained malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - activecritical
Malware in @vite-js/vui
The npm package @vite-js/vui contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in @vite-js/ui
Malware discovered in the npm package @vite-js/ui. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in @tqm-mfe/main
Malware discovered in the npm package @tqm-mfe/main. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in uac-package
Malware was discovered in the npm package uac-package, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-agpl-1-0-only
Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-1-0-only. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-agpl-3-0
Malware was distributed via the npm package @gocortexio/npmgremlinbox-agpl-3-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-apsl
The npm package @gocortexio/npmgremlinbox-apsl contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-base
Malware was discovered in the npm package @gocortexio/npmgremlinbox-base. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, unaffected computer.
npmCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-artistic-1-0
The npm package @gocortexio/npmgremlinbox-artistic-1-0 contained malware that provided full system compromise to attackers. All systems with this package installed should be considered fully compromised and require complete secrets rotation and remediation.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-cc-by-nc-3-0-de
Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-nc-3-0-de, resulting in full system compromise of affected installations. All secrets and keys on compromised systems should be rotated immediately.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-arphic-1999
Malware was distributed via the npm package @gocortexio/npmgremlinbox-arphic-1999. Installation grants full system compromise to an outside entity. All secrets and keys on affected systems must be rotated immediately.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-de
The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-de contained malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-uk
The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-uk contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-fr
The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-fr contained malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-igo
The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-igo contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-cc-by-nd-3-0-de
Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-nd-3-0-de, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-cc-by-sa-3-0-de
Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-sa-3-0-de. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-cc-by-sa-4-0
Malware was discovered in the npm package @gocortexio/npmgremlinbox-cc-by-sa-4-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-igo
Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-igo. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-cdla-sharing-1-0
Malware was discovered in the npm package @gocortexio/npmgremlinbox-cdla-sharing-1-0. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-eupl-1-1
The npm package @gocortexio/npmgremlinbox-eupl-1-1 contained malware that provides full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-epl-2-0
Malware was discovered in the npm package @gocortexio/npmgremlinbox-epl-2-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-lgpl-2-1
The npm package @gocortexio/npmgremlinbox-lgpl-2-1 contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-eupl-3-0
Malware was distributed via the npm package @gocortexio/npmgremlinbox-eupl-3-0. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-epl-1-0
Malware was discovered in the npm package @gocortexio/npmgremlinbox-epl-1-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-mpl-1-1
Malware was discovered in the npm package @gocortexio/npmgremlinbox-mpl-1-1. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-polyform-noncommercial-1-0-0
A malicious npm package @gocortexio/npmgremlinbox-polyform-noncommercial-1-0-0 was published containing malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-malware-install-execution
The npm package @gocortexio/npmgremlinbox-malware-install-execution contained malware capable of achieving full system compromise. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-polyform-small-business-1-0-0
The npm package @gocortexio/npmgremlinbox-polyform-small-business-1-0-0 contains malware that grants full system compromise to an outside entity. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-sspl-1-0
Malware was discovered in the npm package @gocortexio/npmgremlinbox-sspl-1-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.
npmCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-mpl-2-0
Malware was discovered in the npm package @gocortexio/npmgremlinbox-mpl-2-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-typosquat-webpack
Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-webpack, a typosquatting attack. Systems with this package installed are considered fully compromised and require immediate remediation.
npmTyposquattingCompromised package - activecritical
Malware in @gocortexio/npmgremlinbox-linux-man-pages-copyleft
The npm package @gocortexio/npmgremlinbox-linux-man-pages-copyleft contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all credentials rotated immediately.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-typosquat-axios
Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-axios, a typosquat variant. Systems with this package installed are considered fully compromised and require immediate remediation.
npmTyposquattingCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-typosquat-moment
Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-moment, a typosquatting attack. Systems with this package installed are considered fully compromised and require immediate remediation.
npmTyposquattingCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-simpl-2-0
The npm package @gocortexio/npmgremlinbox-simpl-2-0 contained malware that grants full system compromise to attackers. Systems with this package installed should be considered fully compromised and all credentials rotated immediately.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-openpbs-2-3
Malware discovered in npm package @gocortexio/npmgremlinbox-openpbs-2-3. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-malware-network-indicators
The npm package @gocortexio/npmgremlinbox-malware-network-indicators contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets rotated from a different machine.
npmCompromised package - resolvedcritical
Malware in @gocortexio/npmgremlinbox-osl-3-0
The npm package @gocortexio/npmgremlinbox-osl-3-0 contained malware that provided full system compromise to attackers. Systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - containedcritical
Malware in @gocortexio/npmgremlinbox-ms-lpl
The npm package @gocortexio/npmgremlinbox-ms-lpl contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - activecritical
Malware in react-icons-svgo
Malware discovered in the npm package react-icons-svgo. The package is reported to provide full system compromise to any computer where it is installed or running.
npmCompromised package - activecritical
Malware in zoom-widget-xss-poc-paresh
Malware discovered in the npm package zoom-widget-xss-poc-paresh. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in chart-animation-helper
Malware discovered in the npm package chart-animation-helper. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in luludawang-kit
Malware discovered in the npm package luludawang-kit. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - resolvedcritical
Malicious code in solananet (NuGet)
Malicious code was discovered in multiple versions of the solananet NuGet package. The OpenSSF malicious packages project identified and documented the compromise under identifier MAL-2025-191612.
NuGetCompromised package - resolvedcritical
Malicious code in Stl.Rpc.Server.Core (NuGet)
Malicious code was discovered in the Stl.Rpc.Server.Core NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Tessa.Web.Core (NuGet)
Malicious code was discovered in the Tessa.Web.Core NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in PrivacyGate.net (NuGet)
Malicious code was discovered in the PrivacyGate.net NuGet package. The package contained unauthorized code that posed a critical security risk to all consumers.
NuGetCompromised package - resolvedcritical
Malicious code in ZendeskApi.Client.V2 (NuGet)
Malicious code was discovered in multiple versions of the ZendeskApi.Client.V2 NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Portable.Xaml.Net (NuGet)
Malicious code was discovered in multiple versions of the Portable.Xaml.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in OpenAI-Core (NuGet)
Malicious code was discovered in multiple versions of the OpenAI-Core NuGet package. The vulnerability was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in ReaLTaiizor-WinForm (NuGet)
Malicious code was discovered in the ReaLTaiizor-WinForm NuGet package. The OpenSSF malicious packages project identified and documented the compromise under identifier MAL-2024-4624.
NuGetCompromised package - resolvedcritical
Malicious code in Stl.Blazor.Authentication.Net (NuGet)
Malicious code was discovered in the Stl.Blazor.Authentication.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Pathoschild.Stardew.Mod.Build.Config (NuGet)
Malicious code was discovered in the Pathoschild.Stardew.Mod.Build.Config NuGet package. The package was identified by the OpenSSF malicious packages project and published as a critical security advisory.
NuGetCompromised package - containedcritical
SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor
Three RubyGems (git_credential_manager, Dendreo, and fastlane) were compromised to deliver a persistent backdoor named SleeperGem. The malicious packages fetch a second stage payload from a Forgejo C2 server, bypass CI checks, and install a persistent daemon on developer machines.
RubyGemsCompromised packageMalicious maintainer - resolvedcritical
Malicious code in zzlambtestf295 (RubyGems)
Malicious code was discovered in the zzlambtestf295 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-f483-hmjg-2j4m.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzpdfvar05 (RubyGems)
Malicious code was discovered in the zzpdfvar05 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-49pr-q84r-hfv8.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzpdfvar14 (RubyGems)
Malicious code was discovered in the zzpdfvar14 package on RubyGems. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9971.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzfadgivar01 (RubyGems)
Malicious code was discovered in the zzfadgivar01 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-9g95-jm3c-f79g.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzfadgivar05 (RubyGems)
Malicious code was discovered in the zzfadgivar05 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-3gfr-fq7v-cc26.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzjinavcsgit (RubyGems)
Malicious code was published in the zzjinavcsgit RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztargettest18587 (RubyGems)
Malicious code was discovered in the RubyGems package zztargettest18587. The package was identified and documented by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzfadgivar07 (RubyGems)
Malicious code was discovered in the zzfadgivar07 RubyGems package. The package was identified by the OpenSSF malicious packages project and published as advisory GHSA-6xp7-54gh-c547.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzpdfvar11 (RubyGems)
Malicious code was discovered in the zzpdfvar11 RubyGems package. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2026-9968.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzfadgivar11 (RubyGems)
Malicious code was published in the zzfadgivar11 RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzfadgivar04 (RubyGems)
Malicious code was published in the zzfadgivar04 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzfadgivar13 (RubyGems)
Malicious code was published in the zzfadgivar13 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzlambcalx1778552149 (RubyGems)
Malicious code was discovered in the RubyGems package zzlambcalx1778552149. The package was identified and reported by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzsouthhack252269 (RubyGems)
Malicious code was published in the RubyGems package zzsouthhack252269. The package was identified and documented by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzpdfvar13 (RubyGems)
Malicious code was discovered in the zzpdfvar13 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9970.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzpdfvar12 (RubyGems)
Malicious code was discovered in the zzpdfvar12 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9969.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztest1778552006 (RubyGems)
Malicious code was discovered in the RubyGems package zztest1778552006. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzproxyoaiabc431848 (RubyGems)
Malicious code was published in the zzproxyoaiabc431848 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztest17785553733 (RubyGems)
Malicious code was discovered in the RubyGems package zztest17785553733. The package was identified and documented by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztest17785553774 (RubyGems)
Malicious code was published in the zztest17785553774 package on RubyGems. The package was identified and reported by the OpenSSF malicious-packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztxtwtmp12 (RubyGems)
Malicious code was discovered in the zztxtwtmp12 RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztxtwtmp11 (RubyGems)
Malicious code was discovered in the zztxtwtmp11 RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztxtwtmp09 (RubyGems)
Malicious code was published in the zztxtwtmp09 RubyGems package. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Advisory GHSA-g2mw-hc98-7xw3.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztxtwtmp06 (RubyGems)
Malicious code was discovered in the RubyGems package zztxtwtmp06. The package was identified and reported by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzwandtemp1778552518 (RubyGems)
Malicious code was discovered in the RubyGems package zzwandtemp1778552518. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztxtwtmp14 (RubyGems)
Malicious code was published in the zztxtwtmp14 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzpdfvar08 (RubyGems)
Malicious code was discovered in the zzpdfvar08 RubyGems package. The package was identified by the OpenSSF malicious-packages project as containing malicious code.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzfadgivar06 (RubyGems)
Malicious code was discovered in the zzfadgivar06 RubyGems package. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Advisory GHSA-3j6m-654q-8x4q.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzfadgivar10 (RubyGems)
Malicious code was discovered in the zzfadgivar10 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-crg7-g47c-86c6.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzdelay2119 (RubyGems)
Malicious code was discovered in the zzdelay2119 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9935.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztxtwtmp05 (RubyGems)
Malicious code was published in the zztxtwtmp05 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-2pxx-p3xh-qj6q.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzpdfvar04 (RubyGems)
Malicious code was discovered in the zzpdfvar04 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9961.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzpdfvar02 (RubyGems)
Malicious code was discovered in the zzpdfvar02 package on RubyGems. The package contained intentional malicious functionality and was flagged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzjinavcshg (RubyGems)
Malicious code was discovered in the zzjinavcshg RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-5c6q-wgr7-jpmj.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzfadgivar02 (RubyGems)
Malicious code was discovered in the zzfadgivar02 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zwkopt5 (RubyGems)
Malicious code was discovered in the zwkopt5 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zz-oai-test12 (RubyGems)
Malicious code was discovered in the zz-oai-test12 package on RubyGems. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zwpdfg10266a (RubyGems)
Malicious code was published in the zwpdfg10266a RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zwwactb3703 (RubyGems)
Malicious code was published in the RubyGems package zwwactb3703. The package was identified and reported by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zwxbclic (RubyGems)
Malicious code was discovered in the zwxbclic package on RubyGems. The package was identified by the OpenSSF malicious packages project and assigned advisory GHSA-5mv7-2rx3-fjhp.
RubyGemsCompromised package - resolvedcritical
Malicious code in zwmeet017694 (RubyGems)
Malicious code was discovered in the zwmeet017694 RubyGems package. The package was identified by the OpenSSF malicious-packages project and assigned advisory GHSA-54w6-2989-56v7.
RubyGemsCompromised package - resolvedcritical
Malicious code in zwtd102 (RubyGems)
Malicious code was discovered in the zwtd102 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zwtd101 (RubyGems)
Malicious code was discovered in the zwtd101 RubyGems package. The package was identified by the OpenSSF malicious-packages project and assigned advisory GHSA-3fwr-j6xp-prv4.
RubyGemsCompromised package - resolvedcritical
Malicious code in zwxbcstan (RubyGems)
Malicious code was discovered in the zwxbcstan RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zwtlist (RubyGems)
Malicious code was discovered in the zwtlist RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9917.
RubyGemsCompromised package - resolvedcritical
Malicious code in zwtestabc1 (RubyGems)
Malicious code was discovered in the zwtestabc1 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zwtenc1 (RubyGems)
Malicious code was discovered in the zwtenc1 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned advisory GHSA-958h-6v7m-55q9.
RubyGemsCompromised package - resolvedcritical
Malicious code in zwta6000 (RubyGems)
Malicious code was discovered in the zwta6000 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zwpdfg10266b (RubyGems)
Malicious code was discovered in the zwpdfg10266b RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zwxbcsacre (RubyGems)
Malicious code was discovered in the zwxbcsacre RubyGems package. The package was flagged by the OpenSSF malicious packages project and assigned identifier MAL-2026-9931.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztemp-ssf-2605 (RubyGems)
Malicious code was discovered in the zztemp-ssf-2605 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzpdfvar00 (RubyGems)
Malicious code was discovered in the zzpdfvar00 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9957.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztestproxyfooabcxyz (RubyGems)
Malicious code was discovered in the zztestproxyfooabcxyz RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztxtwtmp07 (RubyGems)
Malicious code was discovered in the zztxtwtmp07 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztest17785553661 (RubyGems)
Malicious code was discovered in the RubyGems package zztest17785553661. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzwmgweb02 (RubyGems)
Malicious code was discovered in the zzwmgweb02 RubyGems package. The package was identified by the OpenSSF malicious-packages project and cataloged as MAL-2026-10004.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztest17785553805 (RubyGems)
Malicious code was discovered in the RubyGems package zztest17785553805. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztxtwtmp02 (RubyGems)
Malicious code was discovered in the zztxtwtmp02 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-vjqg-hmmx-fw74.
RubyGemsCompromised package - containedcritical
Malicious code in amzn_consolas_client (crates.io)
The Rust crate amzn-consolas-client version 99.0.1 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.
CargoCompromised package - resolvedcritical
Malicious code in zzzltestfoobarxyz (RubyGems)
Malicious code was published in the zzzltestfoobarxyz RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzpdfvar07 (RubyGems)
Malicious code was discovered in the zzpdfvar07 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9964.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzjinavcsfossil (RubyGems)
Malicious code was published in the zzjinavcsfossil package on RubyGems. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzjinavcsbzr (RubyGems)
Malicious code was discovered in the zzjinavcsbzr RubyGems package. The package was identified by the OpenSSF malicious packages project and published as a security advisory.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzwandsxabc119 (RubyGems)
Malicious code was discovered in the zzwandsxabc119 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - containedcritical
Malicious code in replit_ruspty (crates.io)
The Rust crate replit_ruspty version 1.0.0 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.
CargoCompromised package - resolvedcritical
Malicious code in zzfadgivar09 (RubyGems)
Malicious code was discovered in the zzfadgivar09 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztest4098 (RubyGems)
Malicious code was discovered in the zztest4098 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztest17785553702 (RubyGems)
Malicious code was discovered in the RubyGems package zztest17785553702. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - containedcritical
Malicious code in lsh (crates.io)
The Rust crate 'lsh' version 99.0.1 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.
CargoCompromised package - resolvedcritical
Malicious code in zzpdfvar01 (RubyGems)
Malicious code was discovered in the zzpdfvar01 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9958.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztestno44 (RubyGems)
Malicious code was discovered in the zztestno44 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - containedcritical
Malicious code in semantic_search_client (crates.io)
The Rust crate semantic-search-client version 99.0.1 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.
CargoCompromised package - resolvedcritical
Malicious code in zztxtwtmp08 (RubyGems)
Malicious code was discovered in the zztxtwtmp08 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzpdfvar10 (RubyGems)
Malicious code was discovered in the zzpdfvar10 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9967.
RubyGemsCompromised package - containedcritical
Malicious code in supertag (crates.io)
The Rust crate 'supertag' version 99.1.1 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.
CargoCompromised package - resolvedcritical
Malicious code in zwkopt3 (RubyGems)
Malicious code was discovered in the zwkopt3 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9885.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzpdfvar15 (RubyGems)
Malicious code was discovered in the zzpdfvar15 RubyGems package. The package contained intentional malicious functionality and was identified by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in 866667576576582 (NuGet)
A NuGet package named 866667576576582 was found to contain malicious code. The package was identified and reported by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in zwxbccalag (RubyGems)
Malicious code was discovered in the zwxbccalag RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztestownedtmp1 (RubyGems)
Malicious code was discovered in the zztestownedtmp1 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztxtwtmp10 (RubyGems)
Malicious code was discovered in the zztxtwtmp10 package on RubyGems. The package was identified by the OpenSSF malicious packages project and assigned advisory GHSA-9382-vv7h-xjg3.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzfadgivar03 (RubyGems)
Malicious code was discovered in the zzfadgivar03 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-7pqh-5vxm-7gg2.
RubyGemsCompromised package - resolvedcritical
Malicious code in zwtestabc2 (RubyGems)
Malicious code was discovered in the zwtestabc2 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9911.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzfadgivar12 (RubyGems)
Malicious code was discovered in the zzfadgivar12 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-54hm-p5mv-4hjw.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzpdfvar06 (RubyGems)
Malicious code was discovered in the zzpdfvar06 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-qc82-ff9w-gw63.
RubyGemsCompromised package - resolvedcritical
Malicious code in zwtd104 (RubyGems)
Malicious code was discovered in the zwtd104 RubyGems package. The package was flagged by the OpenSSF malicious packages project and assigned advisory GHSA-x8v6-vchw-7v6h.
RubyGemsCompromised package - containedcritical
Malicious code in proton_pfff (crates.io)
The Rust crate proton-pfff version 99.99.5 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.
CargoCompromised package - containedcritical
Malicious code in mysten_metrics (crates.io)
The Rust crate mysten-metrics version 9.0.3 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.
CargoCompromised package - resolvedcritical
Malicious code in littest (crates.io)
The Rust crate 'littest' version 0.3.1 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.
CargoCompromised package - containedcritical
Malicious code in amzn_codewhisperer_streaming_client (crates.io)
The Rust crate amzn-codewhisperer-streaming-client version 99.0.1 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.
CargoCompromised package - resolvedcritical
Malicious code in zztxtwtmp13 (RubyGems)
Malicious code was discovered in the zztxtwtmp13 RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztxtwtmp01 (RubyGems)
Malicious code was discovered in the zztxtwtmp01 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-hjr8-xr98-g6hc.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztxtwtmp04 (RubyGems)
Malicious code was discovered in the zztxtwtmp04 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-9895-v6m3-rp7r.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzjinavcssvn (RubyGems)
Malicious code was published in the zzjinavcssvn RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-gh85-vrrg-vhq6.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztestno33 (RubyGems)
Malicious code was discovered in the zztestno33 package on RubyGems. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9984.
RubyGemsCompromised package - resolvedcritical
Malicious code in zztxtwtmp03 (RubyGems)
Malicious code was discovered in the zztxtwtmp03 RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzpdfvar03 (RubyGems)
Malicious code was discovered in the zzpdfvar03 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-fjh2-hpmw-wvw7.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzfadgivar08 (RubyGems)
Malicious code was discovered in the zzfadgivar08 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-gf2j-wrw9-h7g7.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzpdfvar09 (RubyGems)
Malicious code was discovered in the zzpdfvar09 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-qj6m-p9hc-6v3r.
RubyGemsCompromised package - resolvedcritical
Malicious code in zzfadgivar00 (RubyGems)
Malicious code was published in the zzfadgivar00 RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.
RubyGemsCompromised package - containedcritical
Malware in anthropic-claude-latest
The npm package anthropic-claude-latest was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in scan-only
The npm package scan-only was found to contain malware, potentially giving full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in axios-native
The npm package axios-native contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in telemetry-axios
Malware was discovered in the npm package telemetry-axios, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.
npmCompromised package - containedcritical
Malware in terminal-mascot
Malware was discovered in the npm package terminal-mascot. Installation or execution of the package results in full system compromise. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.
npmCompromised package - containedcritical
Malware in awesome-terminal
Malware was discovered in the npm package awesome-terminal. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.
npmCompromised package - containedcritical
Malware in theta-sdk-js
Malware was discovered in the theta-sdk-js npm package. Systems with the package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in monogrok
Malware was discovered in the npm package monogrok. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in ai-pro-sdk
Malware discovered in the ai-pro-sdk npm package. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in chain-sdk-js
Malware was distributed through the npm package chain-sdk-js. Systems with the package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in hehehe
The npm package hehehe contained malware that could fully compromise any system where it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in px8my
The npm package px8my was found to contain malware. Installation of this package results in full system compromise with potential for complete control by an external entity.
npmCompromised package - activecritical
Malware in my-tailwind-gutenberg-block
The npm package my-tailwind-gutenberg-block contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in field-plus
The npm package field-plus contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in @sectest429/hello-npm-world
Malware was discovered in the npm package @sectest429/hello-npm-world. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in ai-p2p
Malware discovered in the npm package ai-p2p. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in claude-token-tracker-mcp
The npm package claude-token-tracker-mcp contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in nyt-cms
Malware discovered in the nyt-cms npm package. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in wordpad-text-ui
The npm package wordpad-text-ui contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in loader1
The npm package loader1 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in websight2-p2p
Malware was discovered in the npm package websight2-p2p, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in chai-as-thread
Malware discovered in the npm package chai-as-thread. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.
npmCompromised package - activehigh
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
Russian threat actor UAT-11795 is distributing trojanized versions of WebEx and Zoom applications to deploy Starland RAT malware for credential theft and cryptocurrency theft. The campaign targets users of these widely-used communication platforms.
OtherCompromised package - activecritical
Malware in n8n-nodes-rce-poc
Malware discovered in the npm package n8n-nodes-rce-poc. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different system.
npmCompromised package - containedcritical
Malware in vor8zakon
The npm package vor8zakon was found to contain malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in chai-as-const
Malware was discovered in the npm package chai-as-const. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in websight-p2p
Malware was discovered in the npm package websight-p2p. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in internallib_v907
Malware discovered in the npm package internallib_v907. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @sauruslord/libsignal
Malware discovered in the npm package @sauruslord/libsignal. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in webpack-cache-reset
The npm package webpack-cache-reset contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - resolvedcritical
Malware in saurus-assets
The npm package saurus-assets contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in webpack-cache-cycle
Malware discovered in the npm package webpack-cache-cycle. Any system with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in webpack-session-cache
Malware was discovered in the npm package webpack-session-cache. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @bcs-mi-ui/test1243npmpacket76
Malware was distributed via the npm package @bcs-mi-ui/test1243npmpacket76. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in vite-config-optimizer
Malware discovered in the npm package vite-config-optimizer. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.
npmCompromised package - containedcritical
Malware in js-shared-modules
Malware was discovered in the npm package js-shared-modules. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - activecritical
Malware in @bcs-mi-ui/message-block
Malware discovered in the npm package @bcs-mi-ui/message-block. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in patientdocuments
The npm package patientdocuments contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in zaldy-baileys
Malware was discovered in the npm package zaldy-baileys, resulting in full system compromise for any computer with the package installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.
npmCompromised package - activecritical
Malware in @bcs-mi-ui/message
Malware discovered in the npm package @bcs-mi-ui/message. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in fhirproxy
Malware was discovered in the fhirproxy npm package. Systems with the package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - resolvedcritical
Malware in @saladin0x1/js-shared-modules
Malware was discovered in the npm package @saladin0x1/js-shared-modules. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in true
The npm package 'true' was compromised and distributed with malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - containedcritical
Malware in ldpbootstrap-jquery
Malware was discovered in the npm package ldpbootstrap-jquery. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - resolvedcritical
Malicious code in angylarjs (npm)
Malicious code was discovered in the angylarjs npm package. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Security Advisory GHSA-qqc2-6x9j-cm25.
npmCompromised package - activecritical
Malware in crypto-hasher
Malware discovered in the npm package crypto-hasher. Installation results in full system compromise with potential for complete attacker control and credential theft.
npmCompromised package - activecritical
Malware in yelp-react-component-chaos
Malware discovered in the npm package yelp-react-component-chaos. Systems with this package installed are considered fully compromised and may have given outside entities full control.
npmCompromised package - activecritical
Malware in ssweb-wp
Malware discovered in the npm package ssweb-wp. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in fastify-addon
Malware discovered in the npm package fastify-addon. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @fhkry/baileys
Malware was discovered in the npm package @fhkry/baileys. The package grants full control of affected systems to an outside entity and compromises all secrets and keys stored on those systems.
npmCompromised package - containedcritical
Malware in @sauruslord/eslint-config
Malware was discovered in the npm package @sauruslord/eslint-config. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in textshape-css
Malware discovered in the npm package textshape-css. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in @fhkry/x-baileys
Malware discovered in the npm package @fhkry/x-baileys. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in sauruslord-baileys
The npm package sauruslord-baileys contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in gpu-accelerator
The npm package gpu-accelerator contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in testzapier
Malware was discovered in the npm package testzapier, providing full system compromise to any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.
npmCompromised package - activecritical
Malware in @sauruslord/baileys
The npm package @sauruslord/baileys contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @fhkry/baileys-v2
Malware was discovered in the npm package @fhkry/baileys-v2. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in @achuthvp/postinstall-poc
The npm package @achuthvp/postinstall-poc contained malware that provided full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in fhirproxy-utils
Malware was discovered in the npm package fhirproxy-utils, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.
npmCompromised package - activecritical
Malware in postcss-processor-utils
Malware discovered in the npm package postcss-processor-utils. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.
npmCompromised package - containedcritical
Malware in canary-ci-test
The npm package canary-ci-test was found to contain malware, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @hkyyy/portal-widget-helper-0601
Malware was discovered in the npm package @hkyyy/portal-widget-helper-0601. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malicious code in rhynpm (npm)
The npm package rhynpm was found to contain malicious code. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-5jr8-4283-75xm.
npmCompromised package - resolvedcritical
Malicious code in fflask (PyPI)
Malicious code was published in the fflask package on PyPI. Importing the module triggers an infostealer that exfiltrates data and establishes persistence via autorun directory. The package appears to be a typosquatting attack on a legitimate Flask-related package.
2024 12 ReqesstPyPICompromised packageTyposquatting - containedcritical
​ ​AsyncAPI npm packages infected with credential-stealing malware
Five malicious versions of AsyncAPI npm packages were published in a supply-chain attack delivering a remote access trojan with credential-stealing capabilities. The attack compromised the npm package registry with info-stealing malware.
npmCompromised package - resolvedcritical
Malware in npm-rce-poc
The npm package npm-rce-poc contained malware that granted full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in datefmt-helper
Malware was discovered in the npm package datefmt-helper. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in jscrambler-metro-plugin
Malware was discovered in the npm package jscrambler-metro-plugin. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - containedcritical
Malware in gulp-jscrambler
Malware was discovered in the npm package gulp-jscrambler, resulting in full system compromise for any installation. All secrets and keys on affected systems should be rotated immediately from a clean machine.
npmCompromised package - containedcritical
Malware in eth-lib-utils
Malware was discovered in the npm package eth-lib-utils. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in hashd-edu
The npm package hashd-edu was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in node-path-addon
Malware was discovered in the npm package node-path-addon. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @dsft/ft-utils
Malware was discovered in the npm package @dsft/ft-utils. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @dsft/ft-element
Malware discovered in the npm package @dsft/ft-element. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in iwsdk
Malware was discovered in the npm package iwsdk, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in path-addon-extend
The npm package path-addon-extend was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in assertcoreutils
Malware discovered in the npm package assertcoreutils. Systems with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in ethereum-lib-utils
The npm package ethereum-lib-utils was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and secrets/keys rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in nativescript-swisspost-pcc-creative-editor
Malware was discovered in the npm package nativescript-swisspost-pcc-creative-editor, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in web3-eth-util
Malware was discovered in the npm package web3-eth-util. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - containedcritical
Malware in assertion-utils-js
Malware was discovered in the npm package assertion-utils-js. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in assertcore
The npm package assertcore was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in web3-eth-utils
The npm package web3-eth-utils was compromised and distributed with malware. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in install-skia
The npm package install-skia was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in friendly-greeter-demo
The npm package friendly-greeter-demo contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in nativescript-swisspost-imagepicker
Malware discovered in the npm package nativescript-swisspost-imagepicker. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in tinyparrot
The npm package tinyparrot contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in weavedb-node-client
Malware was discovered in the npm package weavedb-node-client, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in @flcik/flick.js
Malware discovered in the npm package @flcik/flick.js. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in weavedb-client
Malware was discovered in the npm package weavedb-client. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in weavedb-contracts
Malware was discovered in the npm package weavedb-contracts. Systems with this package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - activecritical
Malware in @flex-ng/header-component
Malware discovered in the npm package @flex-ng/header-component. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @logdna-web/styles
Malware was discovered in the npm package @logdna-web/styles. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @flex-ng/filter-pipe
Malware discovered in the npm package @flex-ng/filter-pipe. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @idms-corp/auth-ui
Malware discovered in the npm package @idms-corp/auth-ui. Systems with this package installed are considered fully compromised, with potential for complete system takeover.
npmCompromised package - activecritical
Malware in salesforce-vscode-slds
Malware was discovered in the npm package salesforce-vscode-slds. Any system with this package installed is considered fully compromised and poses a critical risk to stored secrets and keys.
npmCompromised package - containedcritical
Malware in slds-lsp-client
Malware was discovered in the npm package slds-lsp-client, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in box-react-uix
The npm package box-react-uix contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in enbd-react-lib
Malware was discovered in the npm package enbd-react-lib. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in sams-sr-sdk-h5
Malware discovered in the npm package sams-sr-sdk-h5. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in tme-error
The npm package tme-error was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @sflyinc-knapsack/shutterfly-react
Malware was discovered in the npm package @sflyinc-knapsack/shutterfly-react. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, unaffected computer.
npmCompromised package - activecritical
Malware in kraken-ui
The npm package kraken-ui contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in tme-xca
Malware was discovered in the npm package tme-xca. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in flick-test-app
Malware discovered in the npm package flick-test-app. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in weavedb-offchain
Malware was discovered in the npm package weavedb-offchain. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - containedcritical
Malware in @logdna-web/shared
Malware was discovered in the npm package @logdna-web/shared. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @flex-ng/error-component
Malware discovered in the npm package @flex-ng/error-component. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in chat-adapter-zoom
Malware discovered in the npm package chat-adapter-zoom. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.
npmCompromised package - activecritical
Malware in enbd-react-logger
Malware discovered in the npm package enbd-react-logger. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.
npmCompromised package - activecritical
Malware in enbd-react-error-boundry
Malware discovered in the npm package enbd-react-error-boundry. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.
npmCompromised package - activecritical
Malware in tme-xca-react
Malware was discovered in the npm package tme-xca-react. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in @resolvx/core
Malware was discovered in the npm package @resolvx/core. Systems with this package installed or running are considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - activecritical
Malware in @tonsdk/core
Malware was discovered in the npm package @tonsdk/core. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @aonunited/angular
Malware discovered in the npm package @aonunited/angular. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in micro-ui-loader
The npm package micro-ui-loader contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in @cw-ui/asio-neon-themes
Malware discovered in the npm package @cw-ui/asio-neon-themes. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in temp-cloak
Malware was discovered in the npm package temp-cloak, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.
npmCompromised package - activecritical
Malware in string-morph
Malware discovered in the npm package string-morph. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in sight-bind
Malware discovered in the npm package sight-bind. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in avatar-forge
Malware was discovered in the npm package avatar-forge, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a clean system.
npmCompromised package - containedcritical
Malware in dom-weave
Malware was discovered in the npm package dom-weave, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.
npmCompromised package - activecritical
Malware in relative-time-live
The npm package relative-time-live contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in sync-logger
Malware discovered in the npm package sync-logger. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in duration-kit
The npm package duration-kit contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in class-weaver
The npm package class-weaver was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in class-synth
The npm package class-synth was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-c6cg-h94m-mv67 was published on 2026-07-14.
npmCompromised package - activecritical
Malware in @emcd-vue/loans
Malware discovered in the npm package @emcd-vue/loans. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @emcd-vue/auth
Malware was discovered in the npm package @emcd-vue/auth. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @emcd-vue/b2b-pay-form
The npm package @emcd-vue/b2b-pay-form contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in akshajrawat.utils
The npm package akshajrawat.utils contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in @akshajrawat/plugin-repo-cli
Malware discovered in the npm package @akshajrawat/plugin-repo-cli. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @rockawayx/utils
Malware was discovered in the npm package @rockawayx/utils. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @cw-ui/micro-ui-loader
Malware was discovered in the npm package @cw-ui/micro-ui-loader. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in unified-ui-components-library
Malware discovered in the npm package unified-ui-components-library. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in humanize-kit
Malware discovered in the npm package humanize-kit. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in clipboard-drop
The npm package clipboard-drop contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in valid-scope
The npm package valid-scope was found to contain malware, resulting in full system compromise for any computer with the package installed or running. GitHub Security Advisory GHSA-chfc-f2cm-2wf8 was published on 2026-07-14.
npmCompromised package - containedcritical
Malware in @codex2005/logger-core
Malware was discovered in the npm package @codex2005/logger-core. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in @amedit/vercel-builder-probe
Malware was discovered in the npm package @amedit/vercel-builder-probe. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @sqlite-group/schema-generator
The npm package @sqlite-group/schema-generator contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in @sqlite-panel/createsql
The npm package @sqlite-panel/createsql contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @sqlite-clone/nodesql
Malware was discovered in the npm package @sqlite-clone/nodesql. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedhigh
M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions
M-Red-Team compromised AsyncAPI npm packages via GitHub Actions, injecting malicious code into the supply chain. The attack leveraged build system access to distribute compromised packages to downstream consumers.
M Red TeamnpmOtherCompromised packageBuild-system compromise - containedcritical
Malware in @sqlite-group/sql-creator
Malware was discovered in the npm package @sqlite-group/sql-creator. Systems with this package installed are considered fully compromised, with potential for complete system takeover.
npmCompromised package - resolvedcritical
Malware in @oliviamcdaniel12/safer-buffer
Malware was discovered in the npm package @oliviamcdaniel12/safer-buffer. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - containedcritical
Malware in motion-pull
The npm package motion-pull was found to contain malware. Any system with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.
npmCompromised package - containedcritical
Malware in nodemon-delog
The npm package nodemon-delog was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in nodemon-plint
The npm package nodemon-plint contained malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised and all credentials rotated immediately.
npmCompromised package - containedcritical
Malware in @ayunlove/bails
The npm package @ayunlove/bails was found to contain malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in ts-linter-builders
The npm package ts-linter-builders contained malware that could fully compromise affected systems. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in monitoring-service
The npm package monitoring-service contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in ts-biginteger-lib
Malware was discovered in the npm package ts-biginteger-lib. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in monitoring-service-util
The npm package monitoring-service-util contained malware that could fully compromise any system where it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in node-fsmetrics-native
Malware was discovered in the npm package node-fsmetrics-native, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.
npmCompromised package - containedcritical
Malware in node-fsagent
Malware was discovered in the npm package node-fsagent. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in node-fsmetrics-data
Malware was discovered in the npm package node-fsmetrics-data. Systems with this package installed or running are considered fully compromised, with potential for complete system control by an external entity.
npmCompromised package - activecritical
Malware in json-bigint-extend
Malware discovered in the npm package json-bigint-extend. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malicious code in moonskin (npm)
The npm package moonskin was found to contain malicious code that communicates with a domain associated with malicious activity. The package was published to the npm registry and poses a supply chain risk to any project that installed affected versions.
npmCompromised package - containedcritical
Malware in jsonfb
Malware was discovered in the npm package jsonfb, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malicious code in github.com/BufferZoneCorp/go-weather-sdk (Go)
The Go package github.com/BufferZoneCorp/go-weather-sdk contains malicious code that steals credentials, establishes SSH access, and tampers with build and workflow environment variables. It is part of a broader cluster of malicious packages affecting both Go and RubyGems ecosystems.
GoCompromised packageMalicious maintainer - activecritical
Malicious code in github.com/BufferZoneCorp/go-metrics-sdk (Go)
The Go package github.com/BufferZoneCorp/go-metrics-sdk contains malicious code that steals credentials, establishes SSH access, and tampers with build and workflow environment variables. The package is part of a broader malicious cluster affecting both Go and RubyGems ecosystems.
GoCompromised packageMalicious maintainer - resolvedcritical
Malicious code in github.com/belatedplanet/hypert (Go)
A malicious Go package github.com/belatedplanet/hypert was identified as a typosquatting attack targeting Linux and macOS systems. The package functioned as a loader to download and execute additional malicious payloads.
GoTyposquattingCompromised package - activecritical
Malicious code in github.com/BufferZoneCorp/go-stdlib-ext (Go)
The Go package github.com/BufferZoneCorp/go-stdlib-ext contains malicious code that steals credentials, establishes SSH access, and tampers with build and workflow environment variables. The package is part of a broader cluster of malicious packages affecting both Go and RubyGems ecosystems.
GoCompromised packageMalicious maintainer - activecritical
Malicious code in github.com/BufferZoneCorp/go-stdlog (Go)
The Go package github.com/BufferZoneCorp/go-stdlog contains malicious code that steals credentials, establishes SSH access, and tampers with build and workflow environment variables. It is part of a broader cluster of malicious packages affecting both Go and RubyGems ecosystems.
GoCompromised packageMalicious maintainer - activecritical
Malicious code in github.com/BufferZoneCorp/go-retryablehttp (Go)
Malicious code was discovered in the Go package github.com/BufferZoneCorp/go-retryablehttp. The package steals credentials, establishes SSH access, and tampers with build and workflow environment variables. It is part of a broader cluster of malicious packages affecting both Go and RubyGems ecosystems.
GoCompromised packageMalicious maintainer - containedcritical
Malicious code in github.com/utilizedsun/layout (Go)
Malicious Go package github.com/utilizedsun/layout was identified as a typosquatting attack targeting Linux and macOS systems. The package functions as a loader to download and execute additional malicious payloads.
GoTyposquattingCompromised package - resolvedcritical
Malicious code in github.com/vainreboot/layout (Go)
A malicious Go package github.com/vainreboot/layout was published as a typosquatting attack targeting Linux and macOS systems. The package functioned as a loader to download and execute additional malicious payloads.
GoTyposquattingCompromised package - activecritical
Malicious code in github.com/BufferZoneCorp/go-envconfig (Go)
The Go package github.com/BufferZoneCorp/go-envconfig contains malicious code that steals credentials, establishes SSH access, and tampers with build and workflow environment variables. This package is part of a broader malicious cluster affecting both Go and RubyGems ecosystems.
GoCompromised packageMalicious maintainer - containedcritical
Malicious code in github.com/BufferZoneCorp/net-helper (Go)
The Go package github.com/BufferZoneCorp/net-helper contains malicious code that steals credentials, establishes SSH access, and tampers with build/workflow environment variables. This package is part of a broader malicious cluster affecting both Go and RubyGems ecosystems.
GoCompromised packageMalicious maintainer - containedcritical
Malicious code in github.com/BufferZoneCorp/config-loader (Go)
The Go package github.com/BufferZoneCorp/config-loader was identified as malicious, part of a cluster of packages designed to steal credentials, establish SSH access, and tamper with build and workflow environment variables. The package was flagged by Google's open-source security research.
GoCompromised packageMalicious maintainer - activecritical
Malicious code in github.com/boltdb-go/bolt (Go)
github.com/boltdb-go/bolt is a malicious Go package that typosquats the legitimate BoltDB library. It contains a backdoor enabling remote code execution on systems that install it.
GoTyposquattingCompromised package - activecritical
Malicious code in github.com/BufferZoneCorp/grpc-client (Go)
The Go package github.com/BufferZoneCorp/grpc-client contains malicious code that steals credentials, establishes SSH access, and tampers with build and workflow environment variables. The package is part of a broader BufferZoneCorp and RubyGems cluster of malicious packages.
GoCompromised packageMalicious maintainer - resolvedcritical
Malicious code in github.com/thankfulmai/hypert (Go)
A malicious Go package github.com/thankfulmai/hypert was published as a typosquatting attack targeting Linux and macOS systems. The package functioned as a loader to download and execute additional malicious payloads.
GoTyposquattingCompromised package - resolvedcritical
Malicious code in github.com/shadowybulk/hypert (Go)
A malicious Go package, github.com/shadowybulk/hypert, was published as a typosquatting attack targeting Linux and macOS systems. The package functioned as a loader to download and execute additional malicious payloads.
GoTyposquattingCompromised package - resolvedcritical
Malicious code in github.com/ornatedoctrin/layout (Go)
A malicious Go package github.com/ornatedoctrin/layout was identified as a typosquatting attack targeting Linux and macOS systems. The package functioned as a loader to download and execute additional malicious payloads.
GoTyposquattingCompromised package - resolvedcritical
Malicious code in github.com/shallowmulti/hypert (Go)
A malicious Go package github.com/shallowmulti/hypert was published as a typosquatting attack, designed to act as a loader for downloading and executing additional malicious payloads on Linux and macOS systems. The package was identified and reported via the GitHub Advisory Database.
GoTyposquattingCompromised package - containedcritical
Malicious code in github.com/BufferZoneCorp/log-core (Go)
The Go package github.com/BufferZoneCorp/log-core was identified as malicious, part of a cluster that steals credentials, establishes SSH access, and tampers with build/workflow environment variables. The package was flagged by Google's open-source security research.
GoCompromised packageMalicious commit - containedcritical
Malware in nottuff12
The npm package nottuff12 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff3
The npm package nottuff3 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in pure-folder-three
The npm package pure-folder-three was found to contain malware. Installation of the package results in full system compromise, requiring immediate removal and credential rotation from a clean system.
npmCompromised package - activecritical
Malware in dotnet-runtime-base
Malware discovered in the npm package dotnet-runtime-base. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in node-sysmetrics
Malware was discovered in the npm package node-sysmetrics, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.
npmCompromised package - containedcritical
Malware in decimal-format-core
The npm package decimal-format-core was found to contain malware. Any system with this package installed is considered fully compromised and requires immediate remediation.
npmCompromised package - containedcritical
Malware in fpjson-lang
The npm package fpjson-lang was found to contain malware. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate machine.
npmCompromised package - containedcritical
Malware in tipsen-last-pls
Malware was discovered in the npm package tipsen-last-pls, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in another-poc-by-tipsen
The npm package another-poc-by-tipsen contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in tipsen-last
The npm package tipsen-last was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in abuden225
The npm package abuden225 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden21
The npm package abuden21 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in acidic
The npm package acidic was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in abuden223
The npm package abuden223 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden28
The npm package abuden28 contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden211
The npm package abuden211 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in abuden228
The npm package abuden228 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden222
The npm package abuden222 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in abuden214
The npm package abuden214 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden213
The npm package abuden213 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in abuden210
The npm package abuden210 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in sixseven7
The npm package sixseven7 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in sixseven9
The npm package sixseven9 contained malware that could fully compromise any system on which it was installed or running. The package has been identified and removed from distribution.
npmCompromised package - activecritical
Malware in abuden230
The npm package abuden230 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden226
The npm package abuden226 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden227
The npm package abuden227 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in abuden212
The npm package abuden212 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden220
The npm package abuden220 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden224
The npm package abuden224 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden221
The npm package abuden221 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in abuden215
The npm package abuden215 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff22
The npm package nottuff22 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff15
The npm package nottuff15 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in ishowfeet20
The npm package ishowfeet20 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in ishowfeet13
The npm package ishowfeet13 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff10
The npm package nottuff10 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff20
The npm package nottuff20 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in abuden24
The npm package abuden24 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in abuden27
The npm package abuden27 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff28
The npm package nottuff28 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff23
The npm package nottuff23 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden4
The npm package abuden4 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden1
The npm package abuden1 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff27
The npm package nottuff27 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff16
The npm package nottuff16 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff7
The npm package nottuff7 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff9
The npm package nottuff9 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff8
The npm package nottuff8 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden26
The npm package abuden26 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden3
The npm package abuden3 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden23
The npm package abuden23 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden22
The npm package abuden22 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden5
The npm package abuden5 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff29
The npm package nottuff29 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff17
The npm package nottuff17 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff18
The npm package nottuff18 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff14
The npm package nottuff14 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff6
The npm package nottuff6 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff25
The npm package nottuff25 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff2
The npm package nottuff2 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff21
The npm package nottuff21 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in ishowfeet17
The npm package ishowfeet17 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in ishowfeet15
The npm package ishowfeet15 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in speed5
The npm package speed5 contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in sixseven5
The npm package sixseven5 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in speed1
The npm package speed1 contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in sixseven3
The npm package sixseven3 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in howmanygreatbritain
The npm package howmanygreatbritain contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in imillegal5
The npm package imillegal5 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in speed2
The npm package speed2 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in imillegal1
The npm package imillegal1 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in cwao-units
The npm package cwao-units was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-36rh-p4hx-qrr8 was published on 2026-07-13.
npmCompromised package - containedcritical
Malware in tipsen-poc-again
Malware was discovered in the npm package tipsen-poc-again. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in ratelimitsucks4
The npm package ratelimitsucks4 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in testdonotredeemit
Malware was discovered in the npm package testdonotredeemit. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in sixseven10
The npm package sixseven10 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden218
The npm package abuden218 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in sixseven8
The npm package sixseven8 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in abuden216
The npm package abuden216 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in abuden229
The npm package abuden229 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in abuden217
The npm package abuden217 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden219
The npm package abuden219 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in ishowfeet19
The npm package ishowfeet19 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff1
The npm package nottuff1 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in ishowfeet18
The npm package ishowfeet18 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff11
The npm package nottuff11 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff30
The npm package nottuff30 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden29
The npm package abuden29 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff26
The npm package nottuff26 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff13
The npm package nottuff13 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden2
The npm package abuden2 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in prettier-plugin-base
Malware was discovered in the npm package prettier-plugin-base. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in auto-debug-tool
The npm package auto-debug-tool contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in abuden25
The npm package abuden25 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff5
The npm package nottuff5 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff24
The npm package nottuff24 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff19
The npm package nottuff19 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in nottuff4
The npm package nottuff4 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in ishowfeet14
The npm package ishowfeet14 contains malware that grants full system compromise to an external entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in sixseven6
The npm package sixseven6 was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in imillegal4
The npm package imillegal4 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in timmytuffknuckles6
The npm package timmytuffknuckles6 contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in imillegal3
The npm package imillegal3 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in backupsitetuff9
The npm package backupsitetuff9 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in backupsitetuff10
The npm package backupsitetuff10 contains malware that fully compromises any system on which it is installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @nsub/nitxe
The npm package @nsub/nitxe was found to contain malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in nodemon-async
Malware discovered in the npm package nodemon-async. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in type-async
The npm package type-async contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in kuaishou
The npm package kuaishou was found to contain malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all credentials rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in polymarket-kelly-math-stake
Malware was discovered in the npm package polymarket-kelly-math-stake. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - containedcritical
Malware in @dervix/socket.io
Malware was discovered in the npm package @dervix/socket.io. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - activecritical
Malware in @dervix/engine.io
Malware discovered in the npm package @dervix/engine.io. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @gleamkit/socket.io
Malware was discovered in the npm package @gleamkit/socket.io. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - activecritical
Malware in @gleamkit/engine.io
Malware discovered in the npm package @gleamkit/engine.io. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - containedcritical
Malware in polymarket-stake-kelly-math
Malware was discovered in the npm package polymarket-stake-kelly-math. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @gleamkit/probe
The npm package @gleamkit/probe contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in react-dynammic-table-component
Malware was discovered in the npm package react-dynammic-table-component. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in markdown-editable-table
The npm package markdown-editable-table contains malware that provides full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in remarkable-table
Malware discovered in the npm package remarkable-table. The package is considered to provide full system compromise to any computer where it is installed or running.
npmCompromised package - activecritical
Malware in markable-table
Malware discovered in the npm package markable-table. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in nodemon-sync
The npm package nodemon-sync contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in type-context
The npm package type-context was found to contain malware, resulting in full system compromise for any computer with the package installed or running. GitHub Security Advisory GHSA-rw86-h32r-9xf5 was published on 2026-07-13.
npmCompromised package - activecritical
Malware in @tailwind-ts/eslint-plugin
Malware discovered in the npm package @tailwind-ts/eslint-plugin. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @dervix/ws
The npm package @dervix/ws contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in babel-preset-lib-client
Malware was discovered in the npm package babel-preset-lib-client. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in react-markable-table
Malware discovered in the npm package react-markable-table. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in react-dynamic-table-compenent
Malware discovered in the npm package react-dynamic-table-compenent. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in google-caja-bower
Malware was discovered in the npm package google-caja-bower. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedhigh
Hackers backdoor Jscrambler npm package with infostealer malware
A threat actor published a malicious version of the Jscrambler npm package containing infostealer malware. The compromised package was downloaded approximately 1,500 times before discovery and disclosure by Jscrambler.
npmCompromised package - containedcritical
Malware in polymarket-stake-kelly-math-check
The npm package polymarket-stake-kelly-math-check contained malware that fully compromises any system on which it is installed or running. GitHub Security Advisory GHSA-w387-g22r-3pw7 was published on 2026-07-13.
npmCompromised package - containedcritical
Malware in type-astr
The npm package type-astr was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-q9rm-w335-55w5 was published on 2026-07-13.
npmCompromised package - activecritical
Malware in nodemon-eslint
Malware discovered in the npm package nodemon-eslint. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.
npmCompromised package - activecritical
Malware in nodemon-web
The npm package nodemon-web contains malware that grants full system compromise to an attacker. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in type-swap
The npm package type-swap contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in stella-ai-cli
Malware was discovered in the npm package stella-ai-cli. Systems with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in nodemon-client
Malware discovered in the npm package nodemon-client. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in type-unique
The npm package type-unique was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-h8x5-f48q-v2h7 was published on 2026-07-13.
npmCompromised package - containedcritical
jscrambler npm package publishes malicious preinstall binary
Version 8.14.0 of the jscrambler npm package, the official CLI client for Jscrambler Code Integrity API, was published on July 11, 2026 with a malicious preinstall hook that drops and executes platform-specific native binaries on Linux, Windows, and macOS. The compromise was detected by StepSecurity's AI Release Analyzer immediately upon publication.
npmCompromised package - containedcritical
Malware in auth-next-gen
Malware was discovered in the npm package auth-next-gen. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in authvaultx
Malware discovered in the npm package authvaultx. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @genie-auth/config
Malware was discovered in the npm package @genie-auth/config. Systems with this package installed or running are considered fully compromised, with potential for complete system control by an external entity.
npmCompromised package - activecritical
Malware in babel-eslint-parser-legacy
Malware discovered in the npm package babel-eslint-parser-legacy. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in tokenization-util
Malware discovered in the npm package tokenization-util. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @amtrav/webservice
Malware was discovered in the npm package @amtrav/webservice. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in ue-automation-scripts
Malware was discovered in the npm package ue-automation-scripts. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @att-ebiz/abs-components-bc
Malware was discovered in the npm package @att-ebiz/abs-components-bc. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @higherlogic/ocfe
Malware was discovered in the npm package @higherlogic/ocfe. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in tailwind-animate-v4
Malware discovered in the npm package tailwind-animate-v4. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in dowload_ebok_goodbye_things_by_fumio_sasaki_ptu02
A malicious npm package named dowload_ebok_goodbye_things_by_fumio_sasaki_ptu02 was published containing malware that grants full system compromise to attackers. The package was flagged by GitHub Advisory and requires immediate removal and credential rotation.
npmCompromised package - containedcritical
Malware in dowload_ebok_river_of_time_by_naomi_judd_marcia_wilkie_i1ze3
A malicious npm package named dowload_ebok_river_of_time_by_naomi_judd_marcia_wilkie_i1ze3 was published and distributed, providing full system compromise to any computer with the package installed or running. The package has been identified and flagged in the GitHub Advisory Database.
npmCompromised package - activecritical
Malware in cursed-ecto-d3ab00
Malware discovered in the npm package cursed-ecto-d3ab00. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - containedcritical
Malware in execfences
The npm package execfences was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.
npmCompromised package - containedcritical
Malware in dowload_ebok_programming_in_haskell_second_edition_by_graham_hutton_c19wm
A malicious npm package named dowload_ebok_programming_in_haskell_second_edition_by_graham_hutton_c19wm was published containing malware. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in dowload_ebok_murder_in_plain_english_by_michael_arntfield_marcel_danesi_uleto
A malicious npm package named dowload_ebok_murder_in_plain_english_by_michael_arntfield_marcel_danesi_uleto was published containing malware. Installation grants full system compromise to an outside entity.
npmCompromised package - containedcritical
Malware in ag-charts-test
The npm package ag-charts-test was found to contain malware. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in ryan-pdf-js
Malware was discovered in the npm package ryan-pdf-js. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in dowload_ebok_wrath_of_the_gods_by_j_robert_kennedy_61o88
A malicious npm package named dowload_ebok_wrath_of_the_gods_by_j_robert_kennedy_61o88 was published containing malware. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in dowload_ebok_leila_a_filha_de_charles_by_denise_correa_de_macedo_arnold_de_numiers_o103j
A malicious npm package named dowload_ebok_leila_a_filha_de_charles_by_denise_correa_de_macedo_arnold_de_numiers_o103j was published containing malware. Any system with this package installed is considered fully compromised and requires immediate remediation.
npmCompromised package - containedcritical
Malware in dowload_ebok_superior_spider_man_1_marvel_collection_by_dan_slott_tc3wo
A malicious npm package named "dowload_ebok_superior_spider_man_1_marvel_collection_by_dan_slott_tc3wo" was published containing malware. Any computer with this package installed is considered fully compromised and requires immediate remediation.
npmCompromised package - containedcritical
Malware in epic-internal-tools
Malware was discovered in the npm package epic-internal-tools. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in @redhat-cloud-services/frontend-components-utilities
Malware was discovered in the npm package @redhat-cloud-services/frontend-components-utilities. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in localization-lib
Malware discovered in the npm package localization-lib. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in type-slint
Malware was discovered in the npm package type-slint. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in nodemon-slint
The npm package nodemon-slint contains malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in nodemon-patch
The npm package nodemon-patch contains malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in @businessapp-microsites/apis
Malware was discovered in the npm package @businessapp-microsites/apis. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in es6-codify
Malware was discovered in the npm package es6-codify, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in corporate-front-vue
Malware was discovered in the npm package corporate-front-vue. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in privacy-sdk
Malware was discovered in the npm package privacy-sdk, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.
npmCompromised package - containedcritical
Malware in polymarket-kelly-stake-math
Malware was discovered in the npm package polymarket-kelly-stake-math. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.
npmCompromised package - containedcritical
Malware in workspace-scripts
The npm package workspace-scripts contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in voyager-web
Malware discovered in the npm package voyager-web. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in unreal-horde-dashboard
Malware was discovered in the npm package unreal-horde-dashboard. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in ue-jenkins-buildkite
Malware discovered in the npm package ue-jenkins-buildkite. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in bs58-86
The npm package bs58-86 was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - activecritical
Malware in vps-new-manager
The npm package vps-new-manager contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in paperclip-adapter-helpers
Malware discovered in the npm package paperclip-adapter-helpers. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @redhat-cloud-services/compliance-client
Malware was discovered in the npm package @redhat-cloud-services/compliance-client. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in @luminarycloudinternal/frodo
Malware was discovered in the npm package @luminarycloudinternal/frodo. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - containedcritical
Malware in @luminarycloudinternal/lcvis-st
Malware was discovered in the npm package @luminarycloudinternal/lcvis-st. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in crypto-promiser
The npm package crypto-promiser contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different system.
npmCompromised package - containedcritical
Malware in @redhat-cloud-services/tsc-transform-imports
Malware was discovered in the npm package @redhat-cloud-services/tsc-transform-imports. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @redhat-cloud-services/vulnerabilities-client
Malware was discovered in the npm package @redhat-cloud-services/vulnerabilities-client. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in chai-defender
The npm package chai-defender contains malware that fully compromises any system where it is installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in @redhat-cloud-services/types
Malware was discovered in the npm package @redhat-cloud-services/types. Systems with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @redhat-cloud-services/frontend-components-config
Malware was discovered in the npm package @redhat-cloud-services/frontend-components-config. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @redhat-cloud-services/frontend-components-translations
Malware was discovered in the npm package @redhat-cloud-services/frontend-components-translations. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in workspace-lint
The npm package workspace-lint was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in chai-redirection
Malware discovered in the npm package chai-redirection. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in express-session-kit
Malware was discovered in the npm package express-session-kit. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in searchresults
The npm package searchresults was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.
npmCompromised package - containedcritical
Malware in polipoli-pak
Malware was discovered in the npm package polipoli-pak. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in robomerge
Malware was discovered in the robomerge npm package. Systems with the package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.
npmCompromised package - containedcritical
Malware in type-plint
Malware was discovered in the npm package type-plint, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a clean system.
npmCompromised package - resolvedcritical
Malware in type-elint
The npm package type-elint contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in type-atob
Malware was discovered in the npm package type-atob. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @redhat-cloud-services/frontend-components-notifications
Malware was discovered in the npm package @redhat-cloud-services/frontend-components-notifications. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in polygon-gamma-apis
Malware was discovered in the npm package polygon-gamma-apis. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in @redhat-cloud-services/javascript-clients-shared
Malware was discovered in the npm package @redhat-cloud-services/javascript-clients-shared. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @redhat-cloud-services/notifications-client
Malware was discovered in the npm package @redhat-cloud-services/notifications-client. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in @redhat-cloud-services/patch-client
Malware was discovered in the npm package @redhat-cloud-services/patch-client. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @redhat-cloud-services/hcc-pf-mcp
Malware was discovered in the npm package @redhat-cloud-services/hcc-pf-mcp. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in eslint-jest
Malware discovered in the eslint-jest npm package. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.
npmCompromised package - activecritical
Malware in @redhat-cloud-services/host-inventory-client
Malware was discovered in the npm package @redhat-cloud-services/host-inventory-client. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in nodemon-gulp
Malware discovered in the npm package nodemon-gulp. Any system with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in nodepack-daemon
Malware was discovered in the npm package nodepack-daemon. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @redhat-cloud-services/config-manager-client
Malware was discovered in the npm package @redhat-cloud-services/config-manager-client. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @redhat-cloud-services/frontend-components-advisor-components
Malware was discovered in the npm package @redhat-cloud-services/frontend-components-advisor-components. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @redhat-cloud-services/hcc-kessel-mcp
Malware was discovered in the npm package @redhat-cloud-services/hcc-kessel-mcp. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @redhat-cloud-services/insights-client
Malware was discovered in the npm package @redhat-cloud-services/insights-client. Systems with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @redhat-cloud-services/remediations-client
Malware was discovered in the npm package @redhat-cloud-services/remediations-client. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @redhat-cloud-services/tsc-transform-imports
Malware was discovered in the npm package @redhat-cloud-services/tsc-transform-imports. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in ts-eslint-jest
Malware discovered in the npm package ts-eslint-jest. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @redhat-cloud-services/frontend-components-notifications
Malware was discovered in the npm package @redhat-cloud-services/frontend-components-notifications. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in marked-prettier
Malware was discovered in the npm package marked-prettier. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in polymarket-gamma-apis
Malware was discovered in the npm package polymarket-gamma-apis. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - containedcritical
Malware in polygon-gama-apis
The npm package polygon-gama-apis was found to contain malware, potentially providing full system compromise to attackers. All systems with this package installed should be considered compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in polymarket-apis
Malware was discovered in the npm package polymarket-apis. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - containedcritical
Malware in polymarket-trader-apis
Malware was discovered in the npm package polymarket-trader-apis. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in mdb-vite
Malware was discovered in the npm package mdb-vite. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in base62-86x
The npm package base62-86x contained malware that could fully compromise any system where it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.
npmCompromised package - activecritical
Malware in oem-agentic-shared
The npm package oem-agentic-shared contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmAI agents & skillsCompromised package - containedcritical
Malware in page-info-service
Malware was discovered in the npm package page-info-service, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a different computer.
npmCompromised package - containedcritical
Malware in po-ops-local-dev
The npm package po-ops-local-dev was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-r7j7-4gwg-rg72 was published on 2026-07-10.
npmCompromised package - containedcritical
Malware in housecall-ui
Malware was discovered in the npm package housecall-ui, affecting any computer with the package installed or running. The compromise is considered critical as it may grant full control of affected systems to an outside entity.
npmCompromised package - containedcritical
Malware in mazemap
The npm package mazemap was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.
npmCompromised package - containedcritical
Malware in firefly-utilities-helper
Malware was discovered in the npm package firefly-utilities-helper. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in ng-search-api
Malware was discovered in the npm package ng-search-api. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in motiondnb
Malware was discovered in the npm package motiondnb, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in ltidiconf
The npm package ltidiconf was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in visa-cli-tools
The npm package visa-cli-tools was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in higherlogic-ocfe
Malware discovered in the npm package higherlogic-ocfe. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in commons-ui-styles
The npm package commons-ui-styles contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in txs-builder-lib
Malware was discovered in the npm package txs-builder-lib, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in breeze-feature-flag-poc
Malware was discovered in the npm package breeze-feature-flag-poc. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in feedback-api
The npm package feedback-api contains malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in qlkube
Malware was discovered in the npm package qlkube, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.
npmCompromised package - activecritical
Malware in rabi-snooze-api
Malware discovered in the npm package rabi-snooze-api. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.
npmCompromised package - activecritical
Malware in mchain-sdk
The npm package mchain-sdk contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in nodemon-sudo
The npm package nodemon-sudo contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in clavue-agent-sdk
Malware was discovered in the npm package clavue-agent-sdk, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in myclaude-code
Malware was discovered in the npm package myclaude-code. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - resolvedcritical
Malware in calvuepro
The npm package calvuepro contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in bizapi-portal
The npm package bizapi-portal contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in @kl-starfish/test-01
Malware was distributed via the npm package @kl-starfish/test-01. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in rio-design-tokens
Malware was discovered in the npm package rio-design-tokens. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in clavue
The npm package clavue contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in poc-node-npm
Malware was discovered in the npm package poc-node-npm. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in none123s
The npm package none123s was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in @calm2026/imux
The npm package @calm2026/imux contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in clavuepro
The npm package clavuepro contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in fusion-client
The npm package fusion-client contained malware that provided full system compromise to attackers. Any computer with the package installed should be considered fully compromised and all secrets and keys rotated from a different machine.
npmCompromised package - containedcritical
Malware in tslint-conf
The npm package tslint-conf was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in gitlens
Malware was discovered in the gitlens npm package. Systems with the package installed or running are considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in security-console-ui
Malware was discovered in the npm package security-console-ui. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Injective SDK on npm infected with cryptocurrency wallet stealer
Hackers compromised the Injective Labs SDK GitHub repository and published a malicious npm package that stole cryptocurrency wallet private keys and mnemonic seed phrases from users who installed it.
npmCompromised packageMalicious commit - activecritical
Malware in n8n-nodes-mcputils
Malware was discovered in the npm package n8n-nodes-mcputils. Systems with this package installed or running are considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in airkey-mfa-react
Malware was discovered in the npm package airkey-mfa-react. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in chain-api-sdk
Malware was discovered in the npm package chain-api-sdk. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in tailwind-core
Malware was distributed via the npm package tailwind-core. Systems with the package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Keys
On July 8, 2026, attackers gained access to a trusted developer's npm account and injected backdoored code into 18 packages of the Injective blockchain SDK. The malicious code, disguised as analytics, stole wallet recovery phrases and private keys, exfiltrating them to an attacker-controlled server. The compromise was detected and remediated within an hour.
npmAccount takeoverCompromised package - activecritical
Malware in @vite-ln/build-ts
The npm package @vite-ln/build-ts contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in na-rony
The npm package na-rony was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in rony-testing
The npm package rony-testing contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in vite-json-pwa
Malware was discovered in the npm package vite-json-pwa. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in ams-ssk
The npm package ams-ssk contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in karem-dp
The npm package karem-dp was found to contain malware. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in promo-helper
The npm package promo-helper contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different machine.
npmCompromised package - activecritical
Malware in ts-await
Malware discovered in the npm package ts-await. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in common-tg-service
The npm package common-tg-service was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in nam-os-a-man
The npm package nam-os-a-man contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
Malicious packages impersonating Paysafe, Skrill, and Neteller SDKs were published on npm and PyPI, delivering stealer malware designed to harvest credentials from developers and application users.
npmPyPITyposquattingCompromised package - activecritical
Malware in nodemon-node
The npm package nodemon-node contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - resolvedcritical
Malware in gas-log
The npm package gas-log contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in na-rony-test-karem
The npm package na-rony-test-karem contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in na-rony-test
The npm package na-rony-test contained malware that could fully compromise any system on which it was installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.
npmCompromised package - activecritical
Malware in mci-sdk
Malware discovered in the npm package mci-sdk. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in @engagehub/test-claim
Malware discovered in the npm package @engagehub/test-claim. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in ai-sdk-helpers
The npm package ai-sdk-helpers was found to contain malware, potentially providing full system compromise to attackers. All affected systems should be considered fully compromised and all credentials rotated immediately from a clean machine.
npmAI agents & skillsCompromised package - containedcritical
Malware in runtimedev-link
Malware was discovered in the npm package runtimedev-link. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in syco1
Malware was discovered in the npm package syco1, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in express-deflect
Malware discovered in the npm package express-deflect. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @sqlite-list/sql-creator
Malware discovered in the npm package @sqlite-list/sql-creator. Systems with this package installed are considered fully compromised, with potential for complete system takeover.
npmCompromised package - containedcritical
Malware in sypoi1
The npm package sypoi1 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in wsh4-nmp
The npm package wsh4-nmp was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @engagehub/core
Malware was discovered in the npm package @engagehub/core. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - containedcritical
Malware in whs4_npm_test
The npm package whs4_npm_test contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in typescript-base58
Malware was discovered in the npm package typescript-base58. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @sqlite-list/createsql
Malware discovered in the npm package @sqlite-list/createsql. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @aspect-security/argon2
Malware was discovered in the npm package @aspect-security/argon2. Systems with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in ollama-helpers
The npm package ollama-helpers was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-73pg-hv45-6r54 was published on 2026-07-07.
npmCompromised package - containedcritical
Malware in chai-sdk
Malware was discovered in the chai-sdk npm package. Systems with the package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.
npmCompromised package - activecritical
Malware in crypto-base58
The npm package crypto-base58 was compromised and contains malware. Systems with this package installed are considered fully compromised and all secrets and keys should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in rnx-align-deps
Malware discovered in the npm package rnx-align-deps. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @apexcraft/nano-key
Malware was discovered in the npm package @apexcraft/nano-key. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - containedcritical
Malware in chai-spycore
Malware was discovered in the npm package chai-spycore, affecting any computer with the package installed or running. The compromise is considered critical as it grants full system control to an outside entity.
npmCompromised package - containedcritical
Malware in load-nuxt
The npm package load-nuxt was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in polytrade
The npm package polytrade was found to contain malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in chai-chain-dom
Malware was discovered in the npm package chai-chain-dom. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.
npmCompromised package - activecritical
Malware in zod-pino434
The npm package zod-pino434 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in vps-maintenance
The npm package vps-maintenance contained malware that provided full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in base58-cli
The npm package base58-cli was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in gen-ai-opt-in
The npm package gen-ai-opt-in was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-jwrj-q2c7-8g47 was published on 2026-07-07.
npmCompromised package - activecritical
Malware in paperclip2
Malware was discovered in the npm package paperclip2. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - activecritical
Malware in vps-adapter-core
Malware discovered in the npm package vps-adapter-core. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in warp-dependency
The npm package warp-dependency contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @43uh3ig43/telemetry-client
Malware was discovered in the npm package @43uh3ig43/telemetry-client. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in hello244a
The npm package hello244a contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in wsh4_npm
The npm package wsh4_npm contained malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in zredis-typed
The npm package zredis-typed was found to contain malware. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - activecritical
Malware in vps-maintenance-paperclip-adapter
Malware discovered in the npm package vps-maintenance-paperclip-adapter. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in whs4_pnm
The npm package whs4_pnm contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @sqlite-list/schema-generator
Malware was discovered in the npm package @sqlite-list/schema-generator. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.
npmCompromised package - activecritical
Malware in whs4_npm
Malware discovered in the npm package whs4_npm. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in notifier-utils
Malware discovered in the npm package notifier-utils. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in base58-core
Malware was discovered in the npm package base58-core. Systems with the package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in openai-agents-helpers
The npm package openai-agents-helpers was found to contain malware. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmAI agents & skillsCompromised package - activecritical
Malware in @whs4/whs4_npm
Malware discovered in the npm package @whs4/whs4_npm. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.
npmCompromised package - activecritical
Malware in jsf-utils
The npm package jsf-utils contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in paperclip-host-utils
Malware discovered in the npm package paperclip-host-utils. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in express-firegate
Malware discovered in the npm package express-firegate. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in harmony-enablers-test-2026
Malware was discovered in the npm package harmony-enablers-test-2026. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.
npmCompromised package - containedcritical
Malware in solana-address-codec
Malware was discovered in the npm package solana-address-codec. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in brunomenozzi-test-pkg
Malware was discovered in the npm package brunomenozzi-test-pkg. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in anthropic-toolkit
Malware was discovered in the npm package anthropic-toolkit. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in mcp-server-pg
Malware discovered in the npm package mcp-server-pg. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in debugcli
The npm package debugcli was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-86fh-6m37-f9v4 was published on 2026-07-07.
npmCompromised package - activecritical
Malware in some-theme
Malware discovered in the npm package some-theme. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @langgraphjs/toolkit
Malware was discovered in the npm package @langgraphjs/toolkit. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in whs4_nmp
The npm package whs4_nmp contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - containedcritical
Malware in hook-augmenting-module
Malware was discovered in the npm package hook-augmenting-module, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.
npmCompromised package - containedcritical
Malware in tx-guard-snap
Malware was discovered in the npm package tx-guard-snap. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in nonexistent-package
Malware discovered in the npm package nonexistent-package. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in annotator-harvardx
The npm package annotator-harvardx contains malware that provides full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in shopify-internel
The npm package shopify-internel was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in load-nuxt-dev
The npm package load-nuxt-dev was found to contain malware. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in tailwindcss-effector
Malware was discovered in the npm package tailwindcss-effector. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in tailwind-animator-scroll
The npm package tailwind-animator-scroll contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in nuxt-fonts-devtools
Malware was discovered in the npm package nuxt-fonts-devtools. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - containedcritical
Malware in evm-typechain
Malware was discovered in the npm package evm-typechain. Systems with this package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - activecritical
Malware in zod-pino444
The npm package zod-pino444 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in pinokio-redis
Malware discovered in the npm package pinokio-redis. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.
npmCompromised package - activecritical
Malware in @sqlite-access/nodesql
Malware discovered in the npm package @sqlite-access/nodesql. Systems with this package installed are considered fully compromised and may have given outside entities full control of the computer.
npmCompromised package - activecritical
Malware in react-check-error
The npm package react-check-error contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in npm-doc-dev
The npm package npm-doc-dev contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets/keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in ether-bn.js
Malware discovered in the ether-bn.js npm package. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in lint-builds
The npm package lint-builds contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in pino-formatter
Malware discovered in the npm package pino-formatter. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in picocolor-logger
Malware was discovered in the npm package picocolor-logger. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in pino-utils
The npm package pino-utils was compromised and distributed with malware. Any system with the package installed should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in pino-sdk-v2
Malware discovered in the npm package pino-sdk-v2. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in pino-pretty-logs
The npm package pino-pretty-logs was found to contain malware. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in metrica-chain
The npm package metrica-chain was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in chai-guard
Malware discovered in the npm package chai-guard. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in log-upgrade
The npm package log-upgrade contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in mjs-biginteger
Malware was discovered in the npm package mjs-biginteger. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in hjs-biginteger
Malware was discovered in the npm package hjs-biginteger, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in logger-beauty
Malware was discovered in the npm package logger-beauty. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.
npmCompromised package - activecritical
Malware in js-unimode
The npm package js-unimode contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in jsontoken-extend
Malware was discovered in the npm package jsontoken-extend. Systems with this package installed should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in modulyn
The npm package modulyn was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in linter-entry
The npm package linter-entry contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in lint-null
The npm package lint-null was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in color-logger-console
The npm package color-logger-console contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in next-bignumber.js
Malware was discovered in the npm package next-bignumber.js. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in debug-glitzs
Malware was discovered in the npm package debug-glitzs. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in df-vision
The npm package df-vision contained malware that could fully compromise any system on which it was installed. GitHub Security Advisory GHSA-wvvx-jr39-8g7j documents the incident as critical severity.
npmCompromised package - containedcritical
Malware in node-env-detector
The npm package node-env-detector was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in npm-eslint-helper
Malware was discovered in the npm package npm-eslint-helper. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in older_morgan
The npm package older_morgan contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in peptideenv
The npm package peptideenv contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in nodepathbalance54
The npm package nodepathbalance54 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in polymarket-onchain-plugin
Malware was discovered in the polymarket-onchain-plugin npm package. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in prettier-logger
The npm package prettier-logger contains malware that grants full control of affected systems. All systems with this package installed should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in pretty-pino-loggers
Malware was discovered in the npm package pretty-pino-loggers. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.
npmCompromised package - activecritical
Malware in random-string-64
The npm package random-string-64 contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in pretty-pino-logger
Malware was discovered in the npm package pretty-pino-logger. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in request-js-validator
Malware discovered in the npm package request-js-validator. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in router-kit
Malware was discovered in the npm package router-kit, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.
npmCompromised package - containedcritical
Malware in sjs-builders
The npm package sjs-builders was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in set-proto-chain
Malware discovered in the npm package set-proto-chain. The package is confirmed to contain malicious code that grants full system compromise to attackers. All systems with this package installed should be considered fully compromised.
npmCompromised package - activecritical
Malware in st-bigintr
The npm package st-bigintr contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in secure-box
The npm package secure-box was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in tailwind-scroller
Malware discovered in the npm package tailwind-scroller. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in styled-text-logger
The npm package styled-text-logger contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - containedcritical
Malware in sjs-biginteger
Malware was discovered in the npm package sjs-biginteger. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - activecritical
Malware in subsearch
The npm package subsearch contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in tailstyle-core
Malware was discovered in the npm package tailstyle-core. Systems with the package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in sleek-pretty
The npm package sleek-pretty was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in st-biginteger
Malware discovered in the npm package st-biginteger. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in sol-sdk
Malware was discovered in the sol-sdk npm package. Any computer with the package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - containedcritical
Malware in stacknova
The npm package stacknova was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in tailwindcss-framer-motion
Malware was discovered in the npm package tailwindcss-framer-motion. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in tailwindcss-svg-helper
Malware was discovered in the npm package tailwindcss-svg-helper. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in tailwindcss-fonttype-inter
The npm package tailwindcss-fonttype-inter contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - containedcritical
Malware in theta-kit
Malware was discovered in the npm package theta-kit, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in test-prettier
The npm package test-prettier contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in color-cli-log
The npm package color-cli-log contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in tracing-str
The npm package tracing-str was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in tailwind-typography-plus
The npm package tailwind-typography-plus contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in ts-bigtn
The npm package ts-bigtn was found to contain malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in theta-connector
Malware was discovered in the npm package theta-connector, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in competion
The npm package 'competion' contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in ts-relayer-pub
Malware was discovered in the npm package ts-relayer-pub. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - activecritical
Malware in ts-build-optimize
Malware discovered in the npm package ts-build-optimize. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in rma-utils
Malware was discovered in the npm package rma-utils, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.
npmCompromised package - containedcritical
Malware in ts-lint-builds
The npm package ts-lint-builds contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in ts-eslinter
Malware was discovered in the ts-eslinter npm package. Systems with the package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer, and the package should be removed.
npmCompromised package - resolvedcritical
Malware in tsliverhome
The npm package tsliverhome contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in ts-lint-builders
Malware was discovered in the npm package ts-lint-builders. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in renderctx
Malware was discovered in the npm package renderctx. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - activecritical
Malware in txs-data
The npm package txs-data contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in twcompose-utils
The npm package twcompose-utils contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in tailwindcss-fonttypo-inter
Malware discovered in the npm package tailwindcss-fonttypo-inter. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in windrule-utils
Malware was discovered in the npm package windrule-utils. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in tailwindcss-animatecss-latest
The npm package tailwindcss-animatecss-latest contained malware that provided full system compromise to attackers. Systems with this package installed should be considered fully compromised and all credentials rotated immediately.
npmCompromised package - activecritical
Malware in vite-plugin-compress-js
Malware discovered in the npm package vite-plugin-compress-js. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in webpack-cache-clean
The npm package webpack-cache-clean contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in unique-id-64
The npm package unique-id-64 was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - activecritical
Malware in normalize-path-seq
Malware discovered in the npm package normalize-path-seq. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.
npmCompromised package - containedcritical
Malware in web-pool
The npm package web-pool was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in wime-zle
The npm package wime-zle contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in vite-plugin-svg-paths
The npm package vite-plugin-svg-paths was compromised and distributed with malware. Any system with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in winston-js-express
The npm package winston-js-express contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in winston-prism
Malware discovered in the npm package winston-prism. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in xnder-sdk-js
Malware discovered in the npm package xnder-sdk-js. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in @jaime9008/math-service
The npm package @jaime9008/math-service contained malware that could fully compromise any system on which it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in lint-builders
The npm package lint-builders contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in log-format-thread
The npm package log-format-thread contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in metrica-node
The npm package metrica-node was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in chalk-pro-logger
The npm package chalk-pro-logger was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in chalki-pretty
Malware discovered in the npm package chalki-pretty. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in polymarket-onchain-sdk
Malware was discovered in the polymarket-onchain-sdk npm package. Systems with the package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in mongoose-json-format
Malware discovered in the npm package mongoose-json-format. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in typedecode
Malware was discovered in the npm package typedecode. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in tailwind-fonttype-inter
Malware was discovered in the npm package tailwind-fonttype-inter. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in syncora
The npm package syncora was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in sjs-lint-build1
Malware discovered in the npm package sjs-lint-build1. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.
npmCompromised package - containedcritical
Malware in motion-lib
The npm package motion-lib was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in sjs-builder
The npm package sjs-builder contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets rotated from a different machine.
npmCompromised package - containedcritical
Malware in safe-validate
The npm package safe-validate was compromised and distributed with malware. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in react-svg-render
Malware discovered in the npm package react-svg-render. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in react-native-template-my-starter
Malware was discovered in the npm package react-native-template-my-starter. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in typescript-util-core
The npm package typescript-util-core was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in @sql-trigger/nodesql
Malware discovered in the npm package @sql-trigger/nodesql. Systems with this package installed are considered fully compromised, with potential for complete system takeover.
npmCompromised package - activecritical
Malware in @sql-access/nodesql
Malware discovered in the npm package @sql-access/nodesql. Systems with this package installed are considered fully compromised, with potential for complete system takeover.
npmCompromised package - containedcritical
Malware in alder_morrgan
The npm package alder_morrgan was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in ts-node-utils
The npm package ts-node-utils was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-mjvg-2r5j-mg76 was published on 2026-07-03.
npmCompromised package - containedcritical
Malware in @jacobtan/decode-sdk
The npm package @jacobtan/decode-sdk contained malware that could fully compromise any system where it was installed or executed. Systems with this package should be considered fully compromised and all secrets and keys rotated from a different computer.
npmCompromised package - containedcritical
Malware in api-ts-utils
Malware was discovered in the npm package api-ts-utils. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in web-api-node
Malware was discovered in the npm package web-api-node. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - containedcritical
Malware in @lodash-en/lodash-en
Malware was discovered in the npm package @lodash-en/lodash-en. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in decode-sdks
The npm package decode-sdks contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in @sqlite-node/createsql
Malware was discovered in the npm package @sqlite-node/createsql. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @node-cloud/create
Malware was discovered in the npm package @node-cloud/create. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in @antoncarlos1/nodelamp
Malware was distributed via the npm package @antoncarlos1/nodelamp, resulting in full system compromise of affected installations. The package has been identified and removed from distribution.
npmCompromised package - containedcritical
Malware in api-node-utils
Malware was discovered in the npm package api-node-utils. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in tailwind-typography-stylecss
Malware discovered in the npm package tailwind-typography-stylecss. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in db-connector-log
Malware discovered in the npm package db-connector-log. Systems with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in db-convertor
Malware discovered in the npm package db-convertor. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.
npmCompromised package - resolvedcritical
Malware in @modhamanish/rn-mm-template
The npm package @modhamanish/rn-mm-template contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - activecritical
Malware in animatecss-postcss-plugin
Malware discovered in the npm package animatecss-postcss-plugin. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in tailwind-animates
Malware was discovered in the npm package tailwind-animates. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in vitest-agent
Malware was discovered in the npm package vitest-agent. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in db-plog
Malware was discovered in the npm package db-plog, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in cache-section-helper
Malware was discovered in the npm package cache-section-helper. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activehigh
New ChocoPoC malware targets researchers via trojanized PoC exploits
Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering ChocoPoC, a Python-based remote access trojan (RAT) capable of executing commands and stealing sensitive data. The campaign is believed to target cybersecurity researchers.
OtherMalicious commitCompromised package - activecritical
Malware in chai-as-persisted
Malware was discovered in the npm package chai-as-persisted. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - containedcritical
Malware in terminal-prettier
Malware was discovered in the npm package terminal-prettier. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in ts-linting-builder
The npm package ts-linting-builder contained malware that could fully compromise affected systems. All systems with this package installed should be considered compromised and all secrets and keys rotated from a different computer.
npmCompromised package - activecritical
Malware in livekit-agents
Malware was discovered in the livekit-agents npm package. Systems with the package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in setup-cicd
The npm package setup-cicd was found to contain malware, potentially giving outside entities full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmOtherCompromised package - containedcritical
Malware in confluent-kafka-javascript
Malware was discovered in the confluent-kafka-javascript npm package. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in nbmolviz-js
Malware was discovered in the npm package nbmolviz-js. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - containedcritical
Malware in awaitly-analyze
The npm package awaitly-analyze was found to contain malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all credentials rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in chai-as-assured
Malware was discovered in the npm package chai-as-assured. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in rs-biginteger
Malware was discovered in the npm package rs-biginteger, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.
npmCompromised package - resolvedcritical
Malware in ts-lint-builders-v2.1
The npm package ts-lint-builders-v2.1 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in rebrandly-domains-search-client
Malware discovered in the npm package rebrandly-domains-search-client. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in brock-loader
Malware was discovered in the npm package brock-loader, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - containedcritical
Malware in agent-starter-pack
Malware was discovered in the npm package agent-starter-pack. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in postcss-property-rollup
Malware was discovered in the npm package postcss-property-rollup. The package is considered to provide full system compromise to any computer where it is installed or running.
npmCompromised package - containedcritical
Malware in quoting
The npm package 'quoting' was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-x8q6-66jr-wmp3 was published on 2026-06-30.
npmCompromised package - activecritical
Malware in brock-react-alerts
Malware discovered in the npm package brock-react-alerts. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.
npmCompromised package - containedcritical
Malware in autotel-mcp-instrumentation
Malware was discovered in the npm package autotel-mcp-instrumentation. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in procwire
Malware was discovered in the npm package procwire, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.
npmCompromised package - containedcritical
Malware in awaitly-mongo
The npm package awaitly-mongo was found to contain malware, resulting in full system compromise for any computer with the package installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.
npmCompromised package - activecritical
Malware in ai-sdk-ollama
Malware discovered in the ai-sdk-ollama npm package. Systems with this package installed are considered fully compromised and require immediate remediation.
npmAI agents & skillsCompromised package - activecritical
Malware in autotel-drizzle
Malware discovered in the npm package autotel-drizzle. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in autotel-sentry
Malware was discovered in the npm package autotel-sentry, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.
npmCompromised package - containedcritical
Malware in autotel-plugins
The npm package autotel-plugins was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in autotel-mongoose
Malware was discovered in the npm package autotel-mongoose. Systems with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in autotel-tanstack
Malware was discovered in the npm package autotel-tanstack. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - containedcritical
Malware in autotel-vitest
Malware was discovered in the npm package autotel-vitest. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - containedcritical
Malware in autotel-web
The npm package autotel-web was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in endpointmap
The npm package endpointmap contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in rebrandly-domains-digger
Malware was discovered in the npm package rebrandly-domains-digger, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.
npmCompromised package - activecritical
Malware in autotel-mcp
The npm package autotel-mcp contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in autotel-eventcatalog
Malware was discovered in the npm package autotel-eventcatalog. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in autotel-hono
Malware was discovered in the npm package autotel-hono. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activehigh
Malicious PyPI packages give hackers control of Telegram bot servers
A campaign active since November 2025 has distributed malicious PyPI packages—trojanized Pyrogram forks—targeting Python developers building Telegram bots. The compromised packages allow attackers to read arbitrary files on affected servers.
PyPICompromised packageTyposquatting - containedcritical
Malware in autotel-subscribers
The npm package autotel-subscribers was found to contain malware that grants full system compromise to an outside entity. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in autotel-playwright
Malware was discovered in the npm package autotel-playwright. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in awaitly-libsql
The npm package awaitly-libsql was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - resolvedcritical
Malware in awaitly
The npm package awaitly contained malware that provided full system compromise to attackers. Any system with the package installed should be considered fully compromised and all secrets and keys rotated from a different computer.
npmCompromised package - activecritical
Malware in autotel-pact
The npm package autotel-pact contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in @oec-settlement/react-router
Malware discovered in the npm package @oec-settlement/react-router. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @multformats/multiaddr
Malware was discovered in the npm package @multformats/multiaddr. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @reference-web/pmp-i18n
Malware was discovered in the npm package @reference-web/pmp-i18n. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @partner-apps/ui
Malware was discovered in the npm package @partner-apps/ui. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @rakuten-rewards/messaging-sdk-js
Malware was discovered in the npm package @rakuten-rewards/messaging-sdk-js. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @serasa/core
Malware discovered in the npm package @serasa/core. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @rmlibrary/formatting
Malware was discovered in the npm package @rmlibrary/formatting. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @services-lib/application-http-client
Malware discovered in the npm package @services-lib/application-http-client. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @settle-sea/supporting-documents
Malware discovered in the npm package @settle-sea/supporting-documents. Systems with this package installed are considered fully compromised with potential for complete system control by external entities.
npmCompromised package - containedcritical
Malware in gel-bootstrap
Malware was discovered in the npm package gel-bootstrap. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in autotel-cloudflare
Malware was discovered in the npm package autotel-cloudflare, resulting in full system compromise of any computer with the package installed or running. The package has been flagged as critical and requires immediate removal and credential rotation.
npmCompromised package - containedcritical
Malware in @content-editor/common
Malware was discovered in the npm package @content-editor/common. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @contenteditor-shared/content-editor-common
Malware discovered in the npm package @contenteditor-shared/content-editor-common. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in gx-npm-lib
Malware discovered in the npm package gx-npm-lib. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @anna-money/anna-web-lib
Malware was discovered in the npm package @anna-money/anna-web-lib. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in @cxp-shared/string-utilities
Malware was discovered in the npm package @cxp-shared/string-utilities. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in @hg-aka-prml/tapas-common
Malware was discovered in the npm package @hg-aka-prml/tapas-common, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in @epsteinlovekids483/crossmint-wallets-sdk-pentest
Malware was distributed via the npm package @epsteinlovekids483/crossmint-wallets-sdk-pentest. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in gx-npm-feature-flags
Malware was discovered in the npm package gx-npm-feature-flags. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in @fed-sofia/jetify
Malware discovered in the npm package @fed-sofia/jetify. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @img-hls/vtt.js
Malware discovered in the npm package @img-hls/vtt.js. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @meego-progressive/cdk
Malware discovered in the npm package @meego-progressive/cdk. Systems with this package installed are considered fully compromised with potential for complete system takeover.
npmCompromised package - containedcritical
Malware in ts-einkle-slot
Malware was discovered in the npm package ts-einkle-slot. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in @ms-ows/logging
Malware discovered in the npm package @ms-ows/logging. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @e50/utils
The npm package @e50/utils was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @postman-app-monolith/renderer
Malware was discovered in the npm package @postman-app-monolith/renderer. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - resolvedcritical
Malware in velocityfix
The npm package velocityfix contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @riskine-frontend/design-elements
Malware was discovered in the npm package @riskine-frontend/design-elements. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @report-portal/service-ui
Malware was discovered in the npm package @report-portal/service-ui. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - activecritical
Malware in ts-einkle
Malware discovered in the npm package ts-einkle. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @vpms/design-system
Malware was discovered in the npm package @vpms/design-system. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in gx-npm-ui
Malware was discovered in the npm package gx-npm-ui, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in @piewasm/pie-web-npm-package
Malware was discovered in the npm package @piewasm/pie-web-npm-package, providing full system compromise to any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.
npmCompromised package - activecritical
Malware in @sec-loans-ui/utils
Malware discovered in the npm package @sec-loans-ui/utils. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in via-city-tools-m-particle
The npm package via-city-tools-m-particle contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in sorenson-webfonts
The npm package sorenson-webfonts contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in ui-ng-components
Malware was discovered in the npm package ui-ng-components. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in polymarket-clob-math
Malware was discovered in the npm package polymarket-clob-math. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in @cseo-hr/trpweb-shared
Malware was discovered in the npm package @cseo-hr/trpweb-shared. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in @bscom/styling
The npm package @bscom/styling contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @citi-icg-171632/citicms-repo-component
The npm package @citi-icg-171632/citicms-repo-component contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - activecritical
Malware in unsafe-malicious-package
Malware discovered in the npm package unsafe-malicious-package. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @webda-infra/search
Malware was discovered in the npm package @webda-infra/search. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @contentprod-authoring/block-manager
Malware was discovered in the npm package @contentprod-authoring/block-manager. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @sixt-payment/form-react
Malware discovered in the npm package @sixt-payment/form-react. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @bodata/angular-client
Malware was discovered in the npm package @bodata/angular-client. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @deel-ui/animation
The npm package @deel-ui/animation was found to contain malware. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in @alerts/components
Malware was distributed via the npm package @alerts/components. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in unleash-js
Malware was discovered in the unleash-js npm package. Systems with the package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - activecritical
Malware in @digitalpharmacist/http-error-util
Malware discovered in the npm package @digitalpharmacist/http-error-util. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in ts-ankle
The npm package ts-ankle was found to contain malware. Any system with the package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.
npmCompromised package - containedcritical
Malware in @deel-core/client-payroll-onboarding-types
Malware was discovered in the npm package @deel-core/client-payroll-onboarding-types. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @webd-infra/query-designer-domain
Malware was discovered in the npm package @webd-infra/query-designer-domain. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in tivo-codelib-a
Malware discovered in the npm package tivo-codelib-a. Installation results in full system compromise with potential for complete attacker control.
npmCompromised package - containedcritical
Malware in path-internal-util
The npm package path-internal-util was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @postidigital-feature/oneaccount-orgadmin-front
Malware was discovered in the npm package @postidigital-feature/oneaccount-orgadmin-front. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in authsessionbridge
The npm package authsessionbridge contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in vkzmn
The npm package vkzmn contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in auth-state-service
Malware was discovered in the npm package auth-state-service. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - containedcritical
Malware in ssr-auth-sync
Malware was discovered in the npm package ssr-auth-sync. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in test-nonmal-pkg-5
Malware was discovered in the npm package test-nonmal-pkg-5. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.
npmCompromised package - containedcritical
Malware in pvd3
Malware was discovered in the npm package pvd3. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in rc-icon
Malware discovered in the npm package rc-icon. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in react-resource-router-next
Malware was discovered in the npm package react-resource-router-next. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.
npmCompromised package - containedcritical
Malware in eslint-plugin-totara
Malware was discovered in the npm package eslint-plugin-totara. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in cdocs-markdoc
Malware was discovered in the npm package cdocs-markdoc. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.
npmCompromised package - resolvedcritical
Malware in @mcconnect/mcc-common-lib
Malware was discovered in the npm package @mcconnect/mcc-common-lib. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @grappi/automations
Malware discovered in the npm package @grappi/automations. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @sumoinc/trashpanda
The npm package @sumoinc/trashpanda contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in @huobi-ui/activity-components
Malware was discovered in the npm package @huobi-ui/activity-components. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @gallup/pc-utils
The npm package @gallup/pc-utils contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in authmatrix
Malware was discovered in the npm package authmatrix, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in alpine-csp
The npm package alpine-csp contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in @live-backstage-im/communication-chat
Malware discovered in the npm package @live-backstage-im/communication-chat. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @finantix/webcomponents
Malware was discovered in the npm package @finantix/webcomponents. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @rakuten-rewards/messaging-sdk
Malware was discovered in the npm package @rakuten-rewards/messaging-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @sentryx-libraries/auth-interceptor
Malware was discovered in the npm package @sentryx-libraries/auth-interceptor. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in autotel-devtools
Malware was discovered in the npm package autotel-devtools. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @druidsoft/botframework-directlinejs
Malware was discovered in the npm package @druidsoft/botframework-directlinejs. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @ddh-libs/analytics
Malware discovered in the npm package @ddh-libs/analytics. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @mc-xp/mc-monolith-js-src-package
The npm package @mc-xp/mc-monolith-js-src-package contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in @orbis-lr-sdk/orbis-lr-sdk
Malware was discovered in the npm package @orbis-lr-sdk/orbis-lr-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @tbe-ui/ides
Malware discovered in the npm package @tbe-ui/ides. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - containedcritical
Malware in @react-thee/rapier
Malware was discovered in the npm package @react-thee/rapier. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @planetlabs/admin-ng
Malware was discovered in the npm package @planetlabs/admin-ng. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in wm-mapper
The npm package wm-mapper contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in uipath-sugar-sell
Malware discovered in the npm package uipath-sugar-sell. Systems with this package installed are considered fully compromised and may have given outside entities full control.
npmCompromised package - activecritical
Malware in @appsource/utils
The npm package @appsource/utils contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in @concerns/i18n
Malware discovered in the npm package @concerns/i18n. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @webda-features/dashboard
Malware discovered in the npm package @webda-features/dashboard. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @bc-workspace/utils
Malware discovered in the npm package @bc-workspace/utils. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @cloudways-lab/unified-design-system
Malware was discovered in the npm package @cloudways-lab/unified-design-system. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @webda-infra-ui/static-images
Malware was discovered in the npm package @webda-infra-ui/static-images. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in autotel-backends
Malware was discovered in the npm package autotel-backends. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in autotel-cli
The npm package autotel-cli was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in @bapiweb-ux/bapi-header
Malware was discovered in the npm package @bapiweb-ux/bapi-header. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in http-uploader-dev
Malware was discovered in the npm package http-uploader-dev, providing full system compromise to any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @flipbit2-bb/test-auth-state
Malware was discovered in the npm package @flipbit2-bb/test-auth-state. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @flipbit2-bb/scope-test
Malware discovered in the npm package @flipbit2-bb/scope-test. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in hrb-cas-auth-js
Malware was discovered in the npm package hrb-cas-auth-js. The package is considered to provide full system compromise to any computer where it is installed or running.
npmCompromised package - containedcritical
Malware in player-theming
The npm package player-theming was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-j229-wx6p-5j43 was published on 2026-06-29.
npmCompromised package - containedcritical
Malware in player-core-ui
Malware was discovered in the npm package player-core-ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in cmp-api-stub
Malware was discovered in the npm package cmp-api-stub. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - activecritical
Malware in app-hotmart-blog-headless
Malware discovered in the npm package app-hotmart-blog-headless. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in hunsterx-package
Malware was discovered in the npm package hunsterx-package, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in cdocs-data
The npm package cdocs-data was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @shoobx/types
Malware was discovered in the npm package @shoobx/types. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @source-row/source-container
Malware discovered in the npm package @source-row/source-container. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in crossmint-wallets-sdk
Malware was discovered in the npm package crossmint-wallets-sdk, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in wac-atl-context
The npm package wac-atl-context was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @gartnerx/gx-npm-messenger-util
Malware was discovered in the npm package @gartnerx/gx-npm-messenger-util. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @ataslkit/profilecard
Malware discovered in the npm package @ataslkit/profilecard. Systems with this package installed are considered fully compromised, with potential for complete system takeover.
npmCompromised package - activecritical
Malware in @shopbop/api-models
Malware was discovered in the npm package @shopbop/api-models. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in ing-web-v5
Malware discovered in the npm package ing-web-v5. The package grants full control of affected systems to an outside entity and should be considered a critical compromise.
npmCompromised package - activecritical
Malware in magwien.sys
Malware discovered in the npm package magwien.sys. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - activecritical
Malware in ltididp1
The npm package ltididp1 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @experian-shared/services
Malware was discovered in the npm package @experian-shared/services. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @gm-rvg/root-config
Malware was discovered in the npm package @gm-rvg/root-config. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in @lexisnexisrisk/insider-threat-platform
Malware was discovered in the npm package @lexisnexisrisk/insider-threat-platform. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in kdrive-utils
The npm package kdrive-utils contains malware that provides full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in zod-pino
Malware discovered in the npm package zod-pino. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in hexo-deployer-wrangler
Malware discovered in the npm package hexo-deployer-wrangler. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in prism-silq
Malware discovered in the npm package prism-silq. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in ai-node-relay
Malware discovered in the npm package ai-node-relay. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - activecritical
Malware in rollup-plugin-polyfill-connect
Malware discovered in the npm package rollup-plugin-polyfill-connect. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in wellnpm
The npm package wellnpm contained malware that provided full system compromise to attackers. Any system with the package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in ref-slot
Malware was discovered in the npm package ref-slot. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in package-uploader
Malware discovered in the npm package package-uploader. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in pump-stream-logger
Malware was discovered in the npm package pump-stream-logger. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.
npmCompromised package - containedcritical
Malware in pino-zod
Malware was discovered in the npm package pino-zod, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.
npmCompromised package - activecritical
Malware in ts-opus
The npm package ts-opus contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in analysis-chart
The npm package analysis-chart was found to contain malware, resulting in full system compromise for any computer with the package installed or running. GitHub Security Advisory GHSA-2h56-6c2c-2475 was published on 2026-06-26.
npmCompromised package - activecritical
Malware in theme-color-picker
The npm package theme-color-picker contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in ttal2ttml
The npm package ttal2ttml was found to contain malware, potentially giving outside entities full control of affected systems. All systems with this package installed should be considered fully compromised.
npmCompromised package - activecritical
Malware in pump-laserstream-parser
Malware discovered in the npm package pump-laserstream-parser. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in tw-style-utils
Malware was discovered in the npm package tw-style-utils. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in vxui-react
Malware was discovered in the npm package vxui-react, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.
npmCompromised package - containedcritical
Malware in weavedb-base
Malware was discovered in the npm package weavedb-base. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in wao
The npm package wao contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in hexo-shoka-swiper
Malware was discovered in the npm package hexo-shoka-swiper, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in ai-node-agent
The npm package ai-node-agent contains malware that grants full system compromise to an outside entity. All systems with this package installed or running should be considered fully compromised.
npmAI agents & skillsCompromised package - containedcritical
Malware in react-icon-svgs
The npm package react-icon-svgs was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in easy-time666
The npm package easy-time666 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in build-tracker-n5p1
Malware discovered in the npm package build-tracker-n5p1. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in ccl-component-resources
Malware was discovered in the npm package ccl-component-resources. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in leo-logger
Malware was discovered in the npm package leo-logger, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a different computer.
npmCompromised package - containedcritical
Malware in leo-streams
Malware was discovered in the npm package leo-streams. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in leo-cache
The npm package leo-cache was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.
npmCompromised package - containedcritical
Malware in leo-connector-mysql
Malware was discovered in the npm package leo-connector-mysql. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in rstreams-shard-util
Malware was discovered in the npm package rstreams-shard-util, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in leo-sdk
Malware was discovered in the leo-sdk npm package. Systems with the package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in serverless-convention
Malware was discovered in the npm package serverless-convention. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in serverless-leo
Malware was discovered in the npm package serverless-leo. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in event-metrics-q3x7
The npm package event-metrics-q3x7 contains malware that grants full system compromise to an outside entity. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in boardflow
Malware was discovered in the npm package boardflow, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in leo-connector-elasticsearch
Malware was discovered in the npm package leo-connector-elasticsearch. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in leo-auth
The npm package leo-auth was found to contain malware. Any system with the package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer, and the package should be removed.
npmCompromised package - containedcritical
Malware in solo-nav
Malware was discovered in the npm package solo-nav, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in leo-cron
Malware was discovered in the leo-cron npm package. Systems with the package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in leo-cli
The npm package leo-cli was compromised and distributed with malware. Systems with the package installed or executed should be considered fully compromised and require complete remediation.
npmCompromised package - containedcritical
Malware in rstreams-metrics
Malware was discovered in the npm package rstreams-metrics. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in leo-connector-mongo
Malware was discovered in the npm package leo-connector-mongo. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in leo-connector-oracle
Malware was discovered in the npm package leo-connector-oracle. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in pathfix
The npm package pathfix contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in easy-time-format
Malware was discovered in the npm package easy-time-format. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised
On June 24, 2026, an attacker published malicious versions of 20 npm packages belonging to the Leo Platform ecosystem in a coordinated attack. All packages contained an identical CI/CD attack toolkit designed to steal secrets from GitHub Actions runners, cloud credential stores, package registries, and password managers, then exfiltrate them via the victim's GitHub token.
npmOtherCompromised package - containedcritical
Malware in @su-doughnym/metrics-js
Malware was discovered in the npm package @su-doughnym/metrics-js. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in data-fetching-client
Malware was discovered in the npm package data-fetching-client. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, uncompromised system.
npmCompromised package - activecritical
Malware in signup-embedder
Malware discovered in the npm package signup-embedder. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in nabisco
The npm package 'nabisco' contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in @su-doughnym/loginui
Malware discovered in the npm package @su-doughnym/loginui. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in nolimit-x
The npm package nolimit-x was compromised and distributed with malware. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in block-slot
The npm package block-slot was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-pg29-x97h-gfr6 was published on 2026-06-25.
npmCompromised package - containedcritical
Malware in two-factor-prompt-lib
Malware was discovered in the npm package two-factor-prompt-lib. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - activecritical
Malware in hs-locale-management
The npm package hs-locale-management contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised.
npmCompromised package - activecritical
Malware in @su-doughnym/react-dlb
The npm package @su-doughnym/react-dlb contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in axl-ui
Malware was discovered in the npm package axl-ui, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.
npmCompromised package - containedcritical
Malware in loadninja-shared
Malware was discovered in the npm package loadninja-shared. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - containedcritical
Malware in ts-grok
Malware was discovered in the ts-grok npm package. Systems with the package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @su-doughnym/hubspot-loginui-poc
The npm package @su-doughnym/hubspot-loginui-poc contained malware that provided full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in atlassian-forge-skills
The npm package atlassian-forge-skills contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - resolvedcritical
Malware in poc-publish-test-su-doughnym
Malware was discovered in the npm package poc-publish-test-su-doughnym. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.
npmCompromised package - activecritical
Malware in @helpcentre/tesco-help
The npm package @helpcentre/tesco-help contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in rapidsearch
The npm package rapidsearch contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in vercel-api-client
Malware was discovered in the npm package vercel-api-client. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.
npmCompromised package - activecritical
Malware in pretie_x2
The npm package pretie_x2 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in evmdotjs
The npm package evmdotjs was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @kl-dolphin/swim
Malware was discovered in the npm package @kl-dolphin/swim, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in @kl-dolphin/jump
Malware was discovered in the npm package @kl-dolphin/jump, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.
npmCompromised package - activecritical
Malware in multer-express
Malware was discovered in the npm package multer-express. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in pretie_x1
The npm package pretie_x1 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in ui-core-system
Malware discovered in the npm package ui-core-system. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in ldapaotest
The npm package ldapaotest was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.
npmCompromised package - containedcritical
Malware in react-campaign-optimizer
Malware was discovered in the npm package react-campaign-optimizer. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in runtime-query
The npm package runtime-query was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-vh6x-853w-4qvp documents the incident.
npmCompromised package - activecritical
Malware in tailwind-textform-fill
Malware discovered in the npm package tailwind-textform-fill. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in normalize-plus
Malware was discovered in the npm package normalize-plus, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in fetch-page-assets
Malware was discovered in the npm package fetch-page-assets. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in eth_accounts
Malware was discovered in the eth_accounts npm package. Any computer with this package installed is considered fully compromised and all secrets and keys should be rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in react-simple-utils-kit
The npm package react-simple-utils-kit contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - activecritical
Malware in node-vfs-polyfill
Malware discovered in the npm package node-vfs-polyfill. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in aes-decode-runner-pro
Malware discovered in the npm package aes-decode-runner-pro. Systems with this package installed are considered fully compromised and may have given outside entities complete control.
npmCompromised package - activecritical
Malware in markdownlint-cli2-fix
Malware was discovered in the npm package markdownlint-cli2-fix. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in html-to-gutenberg
The npm package html-to-gutenberg was found to contain malware. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in date-format-helper2
Malware was discovered in the npm package date-format-helper2. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - activecritical
Malware in vscode-test-web
Malware discovered in the npm package vscode-test-web. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.
npmCompromised package - activecritical
Malware in postcss-minify-selector
Malware discovered in the npm package postcss-minify-selector. The package is considered to provide full system compromise to any computer where it is installed or running.
npmCompromised package - containedcritical
Malware in opt-archetype-check
Malware was discovered in the npm package opt-archetype-check, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in postcss-minify-selector-parser
Malware was discovered in the npm package postcss-minify-selector-parser. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in poly-utils
Malware was discovered in the npm package poly-utils. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in web3-token-helper
Malware was discovered in the npm package web3-token-helper. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.
npmCompromised package - activecritical
Malware in calculate-helper
Malware discovered in the npm package calculate-helper. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.
npmCompromised package - activecritical
Malware in @ravespaceio/rave-engine
Malware discovered in the npm package @ravespaceio/rave-engine. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in cursorai-agent
Malware discovered in the npm package cursorai-agent. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.
npmCompromised package - activecritical
Malware in backoffice-charges-module
Malware discovered in the npm package backoffice-charges-module. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @muaththir/api
Malware discovered in the npm package @muaththir/api. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - activecritical
Malware in @ravespaceio/browser-input
Malware discovered in the npm package @ravespaceio/browser-input. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in aillmgen
Malware discovered in the npm package aillmgen. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in ts-arithmetic-helper
Malware was discovered in the npm package ts-arithmetic-helper, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in parket-flow
Malware discovered in the npm package parket-flow. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in server-parket
The npm package server-parket contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in mjs-eslint-service
Malware was discovered in the npm package mjs-eslint-service, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in ts-sudo
The npm package ts-sudo was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in sync-external
The npm package sync-external contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in chalk-ultra
Malware discovered in the npm package chalk-ultra. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in ts-predict-helper
Malware was discovered in the npm package ts-predict-helper. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in mjs-eslint-helper
The npm package mjs-eslint-helper contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - activecritical
Malware in vitest-cli
Malware discovered in the npm package vitest-cli. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.
npmCompromised package - activecritical
Malware in chai-as-attested
The npm package chai-as-attested contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in chai-as-uphelded
The npm package chai-as-uphelded was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - containedcritical
Malware in datacamp-light
Malware was discovered in the npm package datacamp-light. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in libsignal-node-travatiger
Malware discovered in the npm package libsignal-node-travatiger. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in ts-numbering
Malware discovered in the npm package ts-numbering. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in onboarding-respects-modal
Malware discovered in the npm package onboarding-respects-modal. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in node-fetch-utils
Malware was discovered in the npm package node-fetch-utils. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation from a clean system.
npmCompromised package - containedcritical
Malware in node-slot
The npm package node-slot was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in ts-wross
The npm package ts-wross contained malware that provided full system compromise to attackers. Any computer with the package installed should be considered fully compromised and all secrets and keys rotated from a different machine.
npmCompromised package - containedcritical
Malware in node-core-libs
Malware was discovered in the npm package node-core-libs. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in search-from-search
The npm package search-from-search contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in local-ip-helper
The npm package local-ip-helper was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.
npmCompromised package - containedcritical
Malware in crud-respect
The npm package crud-respect was found to contain malware. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.
npmCompromised package - containedcritical
Malware in setka-editor
Malware was discovered in the npm package setka-editor, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a different computer.
npmCompromised package - activecritical
Malware in carousel-controller-mixin
Malware discovered in the npm package carousel-controller-mixin. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation from a clean machine.
npmCompromised package - activecritical
Malware in new-ecro-1
The npm package new-ecro-1 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in new-solt
The npm package new-solt was found to contain malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in respects-switch
The npm package respects-switch contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in new-mjs-eslint
The npm package new-mjs-eslint contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in new-helper
The npm package new-helper contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in new-eslint-1
Malware was distributed via the npm package new-eslint-1. Systems with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in new-ecro-helper
The npm package new-ecro-helper contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in new-ts-helper
The npm package new-ts-helper contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.
npmCompromised package - activecritical
Malware in new-solt-1
Malware discovered in the npm package new-solt-1. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in eslint-helper-1
Malware was discovered in the npm package eslint-helper-1, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in free-claude
The npm package free-claude contained malware that could fully compromise any system on which it was installed or running. GitHub Security Advisory GHSA-7qpf-5pm7-57rh documents the incident.
npmCompromised package - activecritical
Malware in mddriver
The npm package mddriver contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in node-path-utils
Malware was discovered in the npm package node-path-utils. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - containedcritical
Malware in free-anthropic-claude
The npm package free-anthropic-claude contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.
npmCompromised package - containedhigh
Microsoft links Mastra AI supply chain attack to North Korean hackers
Microsoft attributed a Mastra AI supply chain attack that compromised over 140 npm packages to North Korean hacking group Sapphire Sleet (BlueNoroff). The attack targeted the npm ecosystem and AI development infrastructure.
UNC1069npmAI agents & skillsCompromised packageMalicious maintainer - containedcritical
Malware in ethereum-gas-reporter
Malware was discovered in the ethereum-gas-reporter npm package. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.
npmCompromised package - activecritical
15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers
A coordinated 8-month supply chain attack compromised 15 malicious JetBrains plugins on the official JetBrains Marketplace, stealing AI API keys from approximately 70,000 developers. The credential-stealing code exfiltrated OpenAI, DeepSeek, and SiliconFlow API keys to an attacker-controlled server in Beijing, which remained operational at the time of disclosure.
OtherCompromised packageMalicious maintainer - resolvedcritical
Malware in assert-kit
The npm package assert-kit contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in pretty-logger-js
Malware was discovered in the npm package pretty-logger-js. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in mongoose-jsonify
Malware discovered in the npm package mongoose-jsonify. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in ts-ecro
Malware was discovered in the npm package ts-ecro, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.
npmCompromised package - containedcritical
Malware in ts-ecro-helper
Malware was discovered in the npm package ts-ecro-helper. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - resolvedcritical
Malware in new-ecro
The npm package new-ecro contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in ts-big-ecro
The npm package ts-big-ecro contained malware that fully compromised any system where it was installed. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.
npmCompromised package - containedcritical
Malware in ts-esys
Malware was discovered in the npm package ts-esys. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in eth-util
Malware was discovered in the eth-util npm package. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - resolvedcritical
Malware in npm-sandbox-research-g3h4
Malware was distributed via the npm package npm-sandbox-research-g3h4. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - containedcritical
Malware in npm-sandbox-ping-r9t2
Malware was discovered in the npm package npm-sandbox-ping-r9t2. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @ncurran/sandbox-recon-sys-5b2c
Malware was discovered in the npm package @ncurran/sandbox-recon-sys-5b2c. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @ncurran/sandbox-recon-880538
Malware was distributed via the npm package @ncurran/sandbox-recon-880538. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in npm-sandbox-research-a1b2
Malware was discovered in the npm package npm-sandbox-research-a1b2. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in pkg-telemetry-r4f9
Malware discovered in the npm package pkg-telemetry-r4f9. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in npm-sandbox-research-8b2f
Malware was discovered in the npm package npm-sandbox-research-8b2f. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in npm-sandbox-research-9c4e
The npm package npm-sandbox-research-9c4e contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in npm-sandbox-ping-c8f2a
Malware was distributed via the npm package npm-sandbox-ping-c8f2a. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in metrics-pipeline-d8k2
The npm package metrics-pipeline-d8k2 contains malware that provides full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - activecritical
Malware in metrics-probe-dc85
The npm package metrics-probe-dc85 contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in metrics-probe-77d4
The npm package metrics-probe-77d4 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @ncurran/sandbox-recon-9b2d4f
Malware was discovered in the npm package @ncurran/sandbox-recon-9b2d4f. Systems with this package installed or running should be considered fully compromised, requiring immediate credential rotation and package removal.
npmCompromised package - containedcritical
Malware in postinstall-logger-7x9z
The npm package postinstall-logger-7x9z contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - containedcritical
Malware in type-check-816d
The npm package type-check-816d was found to contain malware, potentially providing full system compromise to attackers. All systems with this package installed should be considered compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in metrics-probe-f256
The npm package metrics-probe-f256 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - containedcritical
Malware in @ncurran/sandbox-recon-uac-4e7c
The npm package @ncurran/sandbox-recon-uac-4e7c contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in data-utils-d703
The npm package data-utils-d703 contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - resolvedcritical
Malware in npm-sandbox-research-f1g2
Malware was discovered in the npm package npm-sandbox-research-f1g2. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.
npmCompromised package - activecritical
Malware in metrics-probe-88ad
The npm package metrics-probe-88ad contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in runtime-metrics-w7k2
Malware discovered in the npm package runtime-metrics-w7k2. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in string-tools-be6c
The npm package string-tools-be6c contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different machine.
npmCompromised package - containedcritical
Malware in intquery
The npm package intquery was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in @rafaelsene01/agent-flow
Malware discovered in the npm package @rafaelsene01/agent-flow. Systems with this package installed are considered fully compromised and require immediate remediation.
npmAI agents & skillsCompromised package - containedcritical
Malware in uidai_reusable_components
Malware was discovered in the npm package uidai_reusable_components. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - activecritical
Malware in @ncurran/sandbox-recon-sys-5f1b
Malware discovered in the npm package @ncurran/sandbox-recon-sys-5f1b. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in parket-slot
Malware was discovered in the npm package parket-slot, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.
npmCompromised package - activecritical
Malware in metrics-probe-64b2
The npm package metrics-probe-64b2 contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - resolvedcritical
Malware in @ncurran/dc-selftest-33afb7
The npm package @ncurran/dc-selftest-33afb7 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @ncurran/sandbox-recon-sys-6a3f
Malware was discovered in the npm package @ncurran/sandbox-recon-sys-6a3f. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in @ncurran/dc-selftest-ba0ad4
The npm package @ncurran/dc-selftest-ba0ad4 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in color-utils-dee0
The npm package color-utils-dee0 contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - resolvedcritical
Malware in npm-sandbox-research-d7e8
Malware was distributed via the npm package npm-sandbox-research-d7e8. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - activecritical
Malware in fmt-helpers-794b
The npm package fmt-helpers-794b contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in parket-helper
Malware was distributed via the parket-helper npm package. Systems with the package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @ncurran/sandbox-recon-7c4e1a
Malware was discovered in the npm package @ncurran/sandbox-recon-7c4e1a. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in npm-sandbox-research-e9f0
Malware was discovered in the npm package npm-sandbox-research-e9f0. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.
npmCompromised package - resolvedcritical
Malware in npm-sandbox-research-c5d6
Malware was distributed via the npm package npm-sandbox-research-c5d6. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - activecritical
Malware in @mastra/voice-playai
Malware was discovered in the npm package @mastra/voice-playai. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - activecritical
Malware in express-validates
The npm package express-validates was compromised and contains malware. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in qrcode-express
Malware discovered in the npm package qrcode-express. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in sodel-pych
Malware discovered in the npm package sodel-pych. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in api-rs-node
Malware was discovered in the npm package api-rs-node. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.
npmCompromised package - activecritical
Malware in @mastra/loggers
Malware was discovered in the npm package @mastra/loggers. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @mastra/observability
Malware was discovered in the npm package @mastra/observability. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @mastra/blaxel
Malware was discovered in the npm package @mastra/blaxel. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in @mastra/agent-builder
Malware was discovered in the npm package @mastra/agent-builder. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmAI agents & skillsCompromised package - containedcritical
Malware in @mastra/stagehand
Malware was discovered in the npm package @mastra/stagehand. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - activecritical
Malware in @mastra/tavily
Malware was discovered in the npm package @mastra/tavily. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in @mastra/claude
The npm package @mastra/claude contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in @mastra/otel-exporter
Malware was discovered in the npm package @mastra/otel-exporter. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @mastra/deployer-vercel
Malware discovered in the npm package @mastra/deployer-vercel. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in chai-as-tokenized
Malware discovered in the npm package chai-as-tokenized. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in @ignacionunez91/keccak24
Malware was discovered in the npm package @ignacionunez91/keccak24. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in @mastra/pinecone
Malware was discovered in the npm package @mastra/pinecone. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - containedcritical
Malware in sort-btree
Malware was discovered in the npm package sort-btree, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @mastra/node-speaker
Malware was discovered in the npm package @mastra/node-speaker. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @mastra/node-audio
Malware was discovered in the npm package @mastra/node-audio. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @mastra/arize
Malware was discovered in the npm package @mastra/arize. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - containedcritical
Malware in @mastra/gcs
Malware was discovered in the npm package @mastra/gcs. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - activecritical
Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosquat
On June 17, 2026, an attacker compromised the @mastra npm organization and injected easy-day-js, a typosquat of the popular dayjs library, as a dependency across 140+ packages. The malicious package contained an obfuscated postinstall dropper that downloaded and executed a second-stage payload from attacker-controlled servers before self-deleting. The affected packages had a combined weekly download count exceeding 1.1 million.
npmCompromised packageTyposquattingMalicious maintainer - activecritical
Malware in @mastra/convex
Malware was discovered in the npm package @mastra/convex. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in @mastra/s3vectors
Malware was discovered in the npm package @mastra/s3vectors. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - containedcritical
Malware in @mastra/upstash
Malware was discovered in the npm package @mastra/upstash. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @mastra/deployer-cloudflare
Malware was discovered in the npm package @mastra/deployer-cloudflare. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @mastra/cloudflare
Malware was discovered in the npm package @mastra/cloudflare. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.
npmCompromised package - activecritical
Malware in @mastra/cursor
Malware discovered in the npm package @mastra/cursor. Systems with this package installed are considered fully compromised with potential for complete system control by external entities.
npmCompromised package - activecritical
Malware in @mastra/deployer-netlify
Malware discovered in the npm package @mastra/deployer-netlify. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @mastra/turbopuffer
Malware was discovered in the npm package @mastra/turbopuffer. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in @mastra/playground-ui
Malware was discovered in the npm package @mastra/playground-ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @mastra/agent-browser
Malware was discovered in the npm package @mastra/agent-browser. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmAI agents & skillsCompromised package - activecritical
Malware in @mastra/temporal
Malware was discovered in the npm package @mastra/temporal. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in @mastra/mcp-registry-registry
Malware was discovered in the npm package @mastra/mcp-registry-registry. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in @mastra/longmemeval
Malware was discovered in the npm package @mastra/longmemeval. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - containedcritical
Malware in @mastra/daytona
Malware was discovered in the npm package @mastra/daytona. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in @mastra/voice-google-gemini-live
Malware discovered in the npm package @mastra/voice-google-gemini-live. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @mastra/google-cloud-pubsub
Malware was discovered in the npm package @mastra/google-cloud-pubsub. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @mastra/voice-openai-realtime
Malware was discovered in the npm package @mastra/voice-openai-realtime. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - activecritical
Malware in @mastra/voice-openai
Malware was discovered in the npm package @mastra/voice-openai. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - activecritical
Malware in qrcode-generator-node
Malware was discovered in the npm package qrcode-generator-node. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in @mastra/voice-google
Malware was discovered in the npm package @mastra/voice-google. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @mastra/voice-aws-nova-sonic
Malware was discovered in the npm package @mastra/voice-aws-nova-sonic. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in @mastra/voice-deepgram
Malware was discovered in the npm package @mastra/voice-deepgram. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover by an external entity.
npmCompromised package - activecritical
Malware in @mastra/e2b
Malware discovered in the npm package @mastra/e2b. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in @mastra/voice-elevenlabs
Malware was discovered in the npm package @mastra/voice-elevenlabs. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in @mastra/react
Malware was discovered in the npm package @mastra/react. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @mastra/docker
Malware was discovered in the npm package @mastra/docker. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - activecritical
Malware in @mastra/redis
Malware was discovered in the npm package @mastra/redis. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - activecritical
Malware in @mastra/mem0
Malware was discovered in the npm package @mastra/mem0. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - containedcritical
Malware in @mastra/github-signals
Malware was discovered in the npm package @mastra/github-signals. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in tailwindcss-animates-css
Malware discovered in the npm package tailwindcss-animates-css. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in terminal-structured-logger
Malware was discovered in the npm package terminal-structured-logger. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in check-ulid
The npm package check-ulid was compromised and contains malware. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in rbac-auth
Malware was discovered in the npm package rbac-auth. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in bign.tsm
The npm package bign.tsm was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - containedcritical
Malware in authcascade
Malware was discovered in the npm package authcascade, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in npmjs-doc-builder
The npm package npmjs-doc-builder was found to contain malware. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in sp-api-dev-assistant-mcp-server
Malware was discovered in the npm package sp-api-dev-assistant-mcp-server. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.
npmCompromised package - containedcritical
Malware in ttspc-server-sample
The npm package ttspc-server-sample contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in janus-flow
Malware was discovered in the npm package janus-flow, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in flow-lending
The npm package flow-lending was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-pgcr-8w67-72j9 was published on 2026-06-16.
npmCompromised package - containedcritical
Malware in janus-ft
The npm package janus-ft was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in flowdefi
Malware was discovered in the npm package flowdefi. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.
npmCompromised package - containedcritical
Malware in flowcardano
Malware was discovered in the npm package flowcardano. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in bodega-sdk
The npm package bodega-sdk was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in websocket-slot
The npm package websocket-slot contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in epm-service-module-v2
Malware discovered in the npm package epm-service-module-v2. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in hot-validation-sdk
Malware was discovered in the npm package hot-validation-sdk. The advisory warns that any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in worker-build
Malware was discovered in the npm package worker-build, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a clean system.
npmCompromised package - activecritical
Malware in pampipes
Malware discovered in the npm package pampipes. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in auth-basic-vault
Malware discovered in the npm package auth-basic-vault. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in lucide-next
Malware was discovered in the lucide-next npm package. Systems with the package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - activecritical
Malware in swplayer-react-sl
The npm package swplayer-react-sl contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in janus-erc20
Malware was discovered in the npm package janus-erc20. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in flow-lending-sdk
Malware was discovered in the npm package flow-lending-sdk. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - containedcritical
Malware in tailwind-typography-style
The npm package tailwind-typography-style contained malware that could fully compromise any system where it was installed. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.
npmCompromised package - containedcritical
Malware in simple-auth-basic
The npm package simple-auth-basic was compromised and distributed with malware. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in fabric-graphics
The npm package fabric-graphics contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in surf-lending
Malware was discovered in the npm package surf-lending. Any system with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in terminal-pretty-logger
Malware was discovered in the npm package terminal-pretty-logger. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in prettier_v1
Malware was discovered in the npm package prettier_v1. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.
npmCompromised package - activecritical
Malware in @monitoring-lib/error-tracking
Malware discovered in the npm package @monitoring-lib/error-tracking. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in browserslist-db-sync
Malware was discovered in the npm package browserslist-db-sync, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in ect-472839-ctf
The npm package ect-472839-ctf contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in vite-enhancer-config
The npm package vite-enhancer-config contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in sn-internal-testjgsakjdkjadkjahsdkjad
Malware was distributed via the npm package sn-internal-testjgsakjdkjadkjahsdkjad. Installation of this package results in full system compromise. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in internallib_v557
Malware discovered in the npm package internallib_v557. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in sb-original
The npm package sb-original contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in vemos-sdk
The npm package vemos-sdk was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in web-model-bridge
Malware discovered in the npm package web-model-bridge. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in sn-internal-test
The npm package sn-internal-test was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in vite-configu-react
Malware discovered in the npm package vite-configu-react. The package grants full control of affected systems to an outside entity and compromises all secrets and keys stored on those systems.
npmCompromised package - activecritical
Malware in ect-839201
The npm package ect-839201 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in vite-config-react
The npm package vite-config-react contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in ecto_module
Malware discovered in the npm package ecto_module. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in ect-472839
The npm package ect-472839 contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in ect-839201-ctf
The npm package ect-839201-ctf contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in index-ulid
The npm package index-ulid was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in internallib_v984
Malware discovered in the npm package internallib_v984. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in internallib_v856
Malware discovered in the npm package internallib_v856. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in mermaid-v11
Malware discovered in the npm package mermaid-v11. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in slow-surf
The npm package slow-surf contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in chai-smart-assert
Malware discovered in the npm package chai-smart-assert. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in shopify-app-bridge-internal
Malware was discovered in the npm package shopify-app-bridge-internal. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in richtext-editor-ui
The npm package richtext-editor-ui contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in ect-654321
Malware discovered in the npm package ect-654321. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in reading-cookies
The npm package reading-cookies was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in optional-cpu-features
Malware was discovered in the npm package optional-cpu-features. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in prettier_v2
Malware discovered in the npm package prettier_v2. Installation results in full system compromise with potential for complete control by external actors.
npmCompromised package - activecritical
Malware in numdifftools
Malware discovered in the npm package numdifftools. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in um4r719-baileys
The npm package um4r719-baileys contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in web-dotenv
Malware discovered in the npm package web-dotenv. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in ecto-spirit-win-k4n8
Malware discovered in the npm package ecto-spirit-win-k4n8. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in ecto-flag-read-m7p2
The npm package ecto-flag-read-m7p2 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in ecto-spectral-leak-8d4e2
Malware was discovered in the npm package ecto-spectral-leak-8d4e2. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in ecto-win-flag-q2m7
Malware discovered in the npm package ecto-win-flag-q2m7. Systems with this package installed are considered fully compromised and may have given outside entities complete control.
npmCompromised package - containedcritical
Malware in sea-bound-siren
The npm package sea-bound-siren contained malware that fully compromised any system where it was installed or running. The package has been identified and removed from distribution.
npmCompromised package - activecritical
Malware in ecto-corsair-flag-x9m4
Malware discovered in the npm package ecto-corsair-flag-x9m4. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in chai-web3-testkit
Malware was discovered in the npm package chai-web3-testkit. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in ecto-rust-read-f3a9c1
Malware was discovered in the npm package ecto-rust-read-f3a9c1. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in ecto-nightly-spirit
The npm package ecto-nightly-spirit contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in ecto-corsair-whisper-6f3b9
Malware discovered in the npm package ecto-corsair-whisper-6f3b9. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in coral-wraith
Malware was discovered in the npm package coral-wraith. Systems with the package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in @malwguy/ecto-corsair-whisper-3d2a7c
The npm package @malwguy/ecto-corsair-whisper-3d2a7c contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in vite-react-toolkit
The npm package vite-react-toolkit contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in transportator
The npm package transportator contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - resolvedcritical
Malware in @tenforce/toolbox-fontmap
Malware was discovered in the npm package @tenforce/toolbox-fontmap, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in @ntnx/nx-react-components
Malware was discovered in the npm package @ntnx/nx-react-components. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in downlynpm
The npm package downlynpm contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.
npmCompromised package - resolvedcritical
Malware in @johntaohunter/forge-jsx
Malware was discovered in the npm package @johntaohunter/forge-jsx. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.
npmCompromised package - containedcritical
Malware in ozonex-sdk
Malware was discovered in the npm package ozonex-sdk. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in ozone-sdk
Malware was discovered in the npm package ozone-sdk, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.
npmCompromised package - activecritical
Malware in forge-jsxy
The npm package forge-jsxy contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in sass-formats
Malware was discovered in the npm package sass-formats. The package is considered to provide full system compromise to any computer where it is installed or running.
npmCompromised package - activecritical
Malware in typeorm-encrypt
Malware discovered in the npm package typeorm-encrypt. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @trackking/core
Malware discovered in the npm package @trackking/core. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in emittery_styled
The npm package emittery_styled was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in @serviceshub/x-web-core
Malware was discovered in the npm package @serviceshub/x-web-core. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @ngt-frontend/widgets-core
Malware was discovered in the npm package @ngt-frontend/widgets-core. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @vivaux/telemetry
Malware was discovered in the npm package @vivaux/telemetry. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @tribe-digital/shopify-starter-theme
Malware was discovered in the npm package @tribe-digital/shopify-starter-theme. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @vtmn-play/react
Malware was discovered in the npm package @vtmn-play/react. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @sazka/web
The npm package @sazka/web contained malware that could fully compromise any system where it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in @marketplace-shared/components
Malware was discovered in the npm package @marketplace-shared/components. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in @hatcha-captcha/core
Malware discovered in the npm package @hatcha-captcha/core. Systems with this package installed are considered fully compromised with potential for complete system takeover.
npmCompromised package - resolvedcritical
Malware in zatzdbai
The npm package zatzdbai contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in hex-type
The npm package hex-type was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-jc42-pxfc-29x3 was published on 2026-06-11.
npmCompromised package - activecritical
Malware in @iobeya/spa-auth
Malware discovered in the npm package @iobeya/spa-auth. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in tailwindcss-animatics
Malware was discovered in the npm package tailwindcss-animatics. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.
npmCompromised package - containedcritical
Malware in tailwindcss-merge
Malware was discovered in the npm package tailwindcss-merge, potentially compromising any system with the package installed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a clean machine.
npmCompromised package - resolvedcritical
Malware in crypto-javascript
Malware was discovered in the npm package crypto-javascript. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in rate-limits-flexible
The npm package rate-limits-flexible was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in rate-limit-flexible
Malware was discovered in the npm package rate-limit-flexible. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in sass-format
The npm package sass-format was compromised and distributed with malware. Any system with the package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in tailwindcss-animotion
Malware was discovered in the npm package tailwindcss-animotion. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.
npmCompromised package - containedcritical
Malware in clsx-tailwind
Malware was discovered in the npm package clsx-tailwind. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - activecritical
Malware in tailwindcss-animates-kit
Malware discovered in the npm package tailwindcss-animates-kit. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in swagger-express-routes
Malware was discovered in the npm package swagger-express-routes. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.
npmCompromised package - containedcritical
Malware in routing-controls
The npm package routing-controls was compromised and distributed with malware. Any system with the package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in react-photo-views
Malware was discovered in the npm package react-photo-views. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in experian-analytics-components
Malware was discovered in the npm package experian-analytics-components. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in justgetit
The npm package justgetit contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @common-stack/generate-plugin
Malware was distributed via the npm package @common-stack/generate-plugin. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in fed-callnative
Malware was discovered in the npm package fed-callnative. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in theta-sdk
The npm package theta-sdk was compromised and distributed with malware. Any system with the package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in google-cloud-secret-manager-config-poc
Malware was discovered in the npm package google-cloud-secret-manager-config-poc. Systems with this package installed should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in rsflows-pexml
Malware was discovered in the npm package rsflows-pexml, resulting in full system compromise for any computer with the package installed or running. The package should be removed and all secrets and keys rotated from a different computer.
npmCompromised package - containedcritical
Malware in sensivity
The npm package sensivity was found to contain malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in polymarket-clob-api
Malware was discovered in the npm package polymarket-clob-api, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in vqlxjmpr
The npm package vqlxjmpr contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.
npmCompromised package - resolvedcritical
Malware in @snowsight/debug-tooling
The npm package @snowsight/debug-tooling contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in @integrations-center/utils
Malware discovered in the npm package @integrations-center/utils. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @visma-net-platform/module-navigator
Malware was discovered in the npm package @visma-net-platform/module-navigator. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in tailwind-dark-mode-kit
Malware was discovered in the npm package tailwind-dark-mode-kit. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in ioredis-typed
Malware discovered in the npm package ioredis-typed. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in ioredis-orm
Malware was discovered in the npm package ioredis-orm. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, uncompromised system.
npmCompromised package - containedcritical
Malware in @web-3d-tool/sdk
Malware was discovered in the npm package @web-3d-tool/sdk, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.
npmCompromised package - activecritical
Malware in forge-jsx2
Malware discovered in the npm package forge-jsx2. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in archetype-style
The npm package archetype-style was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-m9f5-cp7r-48pm documents the incident.
npmCompromised package - resolvedcritical
Malware in mm-ts-utils-client
Malware was discovered in the npm package mm-ts-utils-client. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in pui-diagnostics
Malware was discovered in the npm package pui-diagnostics. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in tw-fluid-type
Malware was discovered in the npm package tw-fluid-type. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in apple-mycelium-fix
Malware was discovered in the npm package apple-mycelium-fix. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in @coterie-baby/common
Malware was discovered in the npm package @coterie-baby/common. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in sitecore-mm-component-style
Malware discovered in the npm package sitecore-mm-component-style. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in paypal-payouts-bridge
Malware was discovered in the npm package paypal-payouts-bridge. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in crypto-hash-sdk
Malware was discovered in the npm package crypto-hash-sdk. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - activecritical
Malware in tailwind-animator
Malware discovered in the npm package tailwind-animator. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in prettier-sdk
Malware was discovered in the npm package prettier-sdk, resulting in full system compromise for any installation. The package grants outside entities complete control of affected systems.
npmCompromised package - activecritical
Malware in csc154-internall-depend
Malware discovered in the npm package csc154-internall-depend. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in crypto-promise-js
Malware was distributed via the npm package crypto-promise-js. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in @easytipsportal/pos-adapters
Malware discovered in the npm package @easytipsportal/pos-adapters. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in get-deps-path
The npm package get-deps-path contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - resolvedcritical
Malware in argoncrypt
The npm package argoncrypt was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in @meme-sdk/trade
Malware discovered in the npm package @meme-sdk/trade. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @validate-sdk/v2
The npm package @validate-sdk/v2 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in ethers-jss
Malware discovered in the npm package ethers-jss. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in coinbase-wallet-utils
Malware was discovered in the npm package coinbase-wallet-utils. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - activecritical
Malware in @solana-launchpad/sdk
Malware discovered in the npm package @solana-launchpad/sdk. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in devkitx
The npm package devkitx contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in solidity-abi
Malware discovered in the npm package solidity-abi. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in npmjs_hardhat-common
Malware was distributed via the npmjs_hardhat-common package on npm. Any computer with this package installed should be considered fully compromised.
npmCompromised package - activecritical
Malware in @easytipsportal/node-helper
Malware discovered in the npm package @easytipsportal/node-helper. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in graphbase-js
Malware was discovered in the npm package graphbase-js. Systems with the package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in npmjs_web3-common
Malware was discovered in the npm package web3-common. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - activecritical
Malware in @validator-sdk/pubkey
Malware discovered in the npm package @validator-sdk/pubkey. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in anaylze-json
Malware was discovered in the npm package anaylze-json. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in security-env-loader
The npm package security-env-loader contained malware that could fully compromise any system where it was installed or executed. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @validate-ethereum-address/core
The npm package @validate-ethereum-address/core was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed should be considered fully compromised.
npmCompromised package - containedcritical
Malware in xnder-sdk
Malware was discovered in the npm package xnder-sdk, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.
npmCompromised package - activecritical
Malware in xnder-wrapper-module
Malware discovered in the npm package xnder-wrapper-module. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - activecritical
Malware in martinez-polygon-clipping-simul-dalton
The npm package martinez-polygon-clipping-simul-dalton contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malware in auth0-templates-scripts-utils
Malware was discovered in the npm package auth0-templates-scripts-utils. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - resolvedcritical
Malware in nw-demo
The npm package nw-demo contained malware that could fully compromise any system where it was installed or executed. GitHub Security Advisory GHSA-hmxw-6c9h-v2h2 was published on 2026-06-10 to alert users of the threat.
npmCompromised package - containedcritical
Malware in npmjs_ethers-common
Malware was discovered in the npm package ethers-common. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - activecritical
Malware in plugin-fastify
Malware discovered in the npm package plugin-fastify. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in nw-demo-utils
Malware was discovered in the npm package nw-demo-utils. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in npmjs_truffle-helper
Malware was discovered in the npm package npmjs_truffle-helper. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in ethers-wordlist
Malware was discovered in the npm package ethers-wordlist. Systems with this package installed are considered fully compromised and require immediate remediation including key rotation and package removal.
npmCompromised package - containedcritical
Malware in npmjs_solc-helper
The npm package npmjs_solc-helper contained malware, potentially granting full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in npmjs_web3-util
Malware discovered in the npm package web3-util. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - containedcritical
Malware in solc-compiler
The npm package solc-compiler was found to contain malware. Any system with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package - containedcritical
Malware in solc-abi
Malware was discovered in the npm package solc-abi, affecting any system with the package installed. The compromise is considered critical, with full system compromise possible.
npmCompromised package - containedcritical
Malware in auth0-templates-scripts
Malware was discovered in the npm package auth0-templates-scripts. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in python-utils
The npm package python-utils was compromised and distributed with malware. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in use-context-selector-tony
The npm package use-context-selector-tony contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in martinez-polygon-clipping-tony
Malware discovered in the npm package martinez-polygon-clipping-tony. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.
npmCompromised package - containedcritical
Malware in react-tracked-tony
Malware was discovered in the npm package react-tracked-tony. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in @builder.io/dev-tools
Malware was discovered in the npm package @builder.io/dev-tools, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in @doaction/auth
Malware discovered in the npm package @doaction/auth. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in comos-sdk
Malware was discovered in the npm package comos-sdk, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a clean system.
npmCompromised package - activecritical
Malware in path-extend
The npm package path-extend contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in void-ulid
Malware was discovered in the npm package void-ulid, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in @doaction/shared
Malware was discovered in the npm package @doaction/shared. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @doaction/http
Malware was discovered in the npm package @doaction/http. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - containedcritical
Malware in @doaction/storage
Malware was discovered in the npm package @doaction/storage. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.
npmCompromised package - activecritical
Malware in @doaction/sudo-prompt
Malware was discovered in the npm package @doaction/sudo-prompt. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @doaction/types
Malware was discovered in the npm package @doaction/types. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in clsx-js
Malware discovered in the npm package clsx-js. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in os-ulid-void
The npm package os-ulid-void was found to contain malware, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in ui-weave
Malware was discovered in the npm package ui-weave, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - containedcritical
Malware in transacts
The npm package transacts was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.
npmCompromised package - containedcritical
Malware in buffer-utilities
Malware was discovered in the npm package buffer-utilities, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.
npmCompromised package - containedcritical
Malware in @doaction/eventemitter
Malware was discovered in the npm package @doaction/eventemitter. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @doaction/example
The npm package @doaction/example contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @doaction/examples
Malware was discovered in the npm package @doaction/examples. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in @doaction/pay
Malware was discovered in the npm package @doaction/pay. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - activecritical
Malware in @doaction/mapstore
The npm package @doaction/mapstore contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in @doaction/systeminformation
The npm package @doaction/systeminformation contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in @doaction/signalhub
Malware was discovered in the npm package @doaction/signalhub. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - containedcritical
Malware in @doaction/rrweb-sdk
Malware was discovered in the npm package @doaction/rrweb-sdk. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.
npmCompromised package - containedcritical
Malware in xorma-js
Malware was discovered in the npm package xorma-js, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.
npmCompromised package - activecritical
Malware in @doaction/wasm-loader
Malware was discovered in the npm package @doaction/wasm-loader. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.
npmCompromised package - activecritical
Malware in kecak256
The npm package kecak256 was compromised and contains malware. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - activecritical
Malware in progerss-cli
Malware discovered in the npm package progerss-cli. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in enquriers
The npm package enquriers was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.
npmCompromised package - containedcritical
Malware in cookie-parser-legacy
Malware was discovered in the npm package cookie-parser-legacy. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - containedcritical
Malware in moustick
Malware was discovered in the npm package moustick, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.
npmCompromised package - containedcritical
Malware in dbmux
Malware was discovered in the npm package dbmux. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.
npmCompromised package - containedcritical
Malware in github-archiver
The npm package github-archiver was found to contain malware. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedhigh
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
Hackers compromised 19 science-focused packages on PyPI in a Shai-Hulud supply-chain attack. The trojanized packages were collectively downloaded hundreds of thousands of times and delivered malware designed to steal developer secrets.
Shai-HuludPyPICompromised package - activecritical
Malware in chai-mocks
Malware discovered in the npm package chai-mocks. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.
npmCompromised package - activecritical
Malware in nodemon-lint
The npm package nodemon-lint contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
Malware in regexp-ts
The npm package regexp-ts contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - activecritical
The Hades Campaign: Graph ML PyPI Packages Deploy Cross-Platform Memory Scrapers, AI Analyst Misdirection, and a Wiper Deterrent
On June 8, 2026, multiple Graph ML PyPI packages were compromised in the Hades campaign, deploying cross-platform memory scrapers, AI prompt injections for analyst misdirection, and token-revocation wipers. The attack targeted the bioinformatics ecosystem with sophisticated evasion techniques.
HadesPyPICompromised package - containedcritical
Malware in nodemon-copack
The npm package nodemon-copack contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package - containedcritical
Malware in classwind-utils
Malware was discovered in the npm package classwind-utils. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - activehigh
New IronWorm malware hits 36 packages in npm supply-chain attack
A supply-chain attack infected 36 packages on npm with IronWorm infostealer malware. The attack compromised multiple packages in the Node Package Manager ecosystem, potentially affecting downstream users and applications.
IronWormnpmCompromised package - containedhigh
Hola Browser for Windows compromised to deliver cryptominer
The Windows version of Hola Browser was compromised in a supply chain attack that delivered an undeclared cryptocurrency miner executable to users. The compromise affected the browser's distribution or update mechanism.
OtherCompromised packageUpdate-server compromise - activecritical
Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp
A self-replicating worm named Miasma is spreading across the npm registry by injecting malicious code into binding.gyp files, which execute during npm install without requiring package.json script modifications. The attack has already compromised dozens of packages across multiple maintainer accounts and evades conventional security detection.
MiasmanpmCompromised packageMalicious commit - containedcritical
Multiple redhat-cloud-services npm Packages compromised
Multiple npm packages in the @redhat-cloud-services scope were compromised with malicious payloads. The attack used preinstall hooks to execute a multi-stage credential harvester targeting cloud and CI/CD platform secrets.
MiasmanpmCompromised package - activehigh
Miasma: Supply Chain Attack Targeting RedHat npm Packages
Miasma is a supply chain attack targeting RedHat npm packages, leveraging malicious npm packages based on the open-sourced Mini Shai-Hulud malware. Specific affected packages and versions were not disclosed in the available source text.
Mini Shai HuludnpmCompromised package - containedcritical
Microsoft's durabletask PyPI Package Compromised in Supply Chain Attack
Three malicious versions of Microsoft's durabletask Python package were published to PyPI on May 19, 2026, containing a 28 KB payload that steals credentials from cloud providers (AWS, Azure, GCP), Kubernetes, password managers, and developer tools. The attack has been attributed to the TeamPCP threat group and exhibits indicators of Eastern European cybercrime operations.
TeamPCPPyPICompromised package - activecritical
Active Supply Chain Attack: Malicious node-ipc Versions Published to npm
StepSecurity identified multiple malicious releases of the popular node-ipc npm package containing an obfuscated payload designed to steal cloud credentials, SSH keys, and CI/CD secrets. The attack is ongoing and under active analysis.
npmCompromised package - activecritical
The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave
TeamPCP conducted a multi-ecosystem supply chain compromise targeting the @antv package and associated development infrastructure. The attack leveraged GitHub, NPM, and VSCode to steal credentials and establish persistence mechanisms.
TeamPCPnpmOtherAccount takeoverCompromised packageMalicious maintainer - activecritical
Shai-Hulud: Here We Go Again. Mass npm Supply Chain Attack Hits the AntV Ecosystem
A new wave of the Mini Shai-Hulud worm has compromised multiple npm packages across Alibaba's AntV data visualization ecosystem, including echarts-for-react and timeago.js. Stolen CI/CD secrets are being exfiltrated and dumped to thousands of public GitHub repositories as the attack spreads.
Mini Shai HuludnpmOtherCompromised packageAccount takeover - resolvedhigh
durabletask: TeamPCP's Latest PyPi Compromise
Malicious versions of the PyPI package durabletask were published, attributed to the TeamPCP threat actor. The attack matches known TeamPCP tactics used in prior supply chain compromises.
TeamPCPPyPICompromised package - activehigh
Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised
A supply chain campaign called "Mini Shai-Hulud" has compromised multiple npm packages, including high-value TanStack developer tooling. The campaign appears to be an ongoing effort targeting critical npm infrastructure.
Mini Shai HuludnpmCompromised package - activecritical
TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages
The Mini Shai-Hulud worm is actively compromising legitimate npm packages by hijacking CI/CD pipelines and stealing developer secrets. The attack was first detected by StepSecurity in official @tanstack packages and is spreading across the npm ecosystem in real time.
TeamPCPMini Shai HuludnpmOtherCompromised packageBuild-system compromise - containedcritical
TeamPCP Injects Two-Stage Credential Stealer into xinference PyPI Package
The xinference package on PyPI was compromised with a two-stage credential stealer attributed to the TeamPCP threat actor. The malicious code was injected into the package, potentially affecting users who installed compromised versions.
TeamPCPPyPICompromised packageMalicious maintainer - activecritical
Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked — 361,000 Weekly Downloads, AWS, GCP, and Azure Credentials Now in Scope
The Shai-Hulud worm has hijacked intercom-client@7.0.4 (361,510 weekly downloads) via a compromised GitHub Actions OIDC publishing pipeline, 29 hours after compromising mbt@1.2.48 and @cap-js/sqlite@2.2.2. The worm is actively propagating through CI/CD infrastructure stolen from earlier victims, targeting multi-cloud credentials (AWS, GCP, Azure).
Shai-HuludnpmOtherCompromised packageBuild-system compromiseAccount takeover - activehigh
A Mini Shai-Hulud Has Appeared: Obfuscated Bun Runtime Payloads Hit SAP-Related npm Packages
StepSecurity identified an npm supply chain attack campaign targeting SAP-ecosystem packages using preinstall hooks to download and execute an obfuscated Bun runtime payload. At least two SAP-related npm packages have been confirmed compromised in this active campaign.
Mini Shai HuludnpmCompromised package - containedcritical
Bitwarden CLI Hijacked on npm: Bun-Staged Credential Stealer Targets Developers, GitHub Actions, and AI Tools
@bitwarden/cli@2026.4.0 was compromised on npm with a malicious preinstall hook that deployed an obfuscated credential stealer. The malware harvests developer secrets, GitHub Actions tokens, and AI tool configurations, exfiltrating encrypted data to a Checkmarx-impersonating domain.
Shai-HuludTeamPCPnpmCompromised package - containedhigh
lightning: Obfuscated JavaScript Credential Stealer Bundled in PyPI Wheel
The lightning PyPI package versions 2.6.2 and 2.6.3 were compromised on April 30, 2026, containing obfuscated JavaScript code designed to steal credentials. The project's GitHub account showed signs of compromise, with suspicious responses closing vulnerability reports.
Mini Shai HuludPyPICompromised packageMalicious maintainer - activehigh
Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware
A supply chain campaign dubbed "Mini Shai Hulud" targeted SAP npm packages with malicious versions containing credential-stealing malware. The campaign follows patterns similar to previous Shai-Hulud attacks.
Mini Shai HuludShai-HuludnpmCompromised packageMalicious commit - activecritical
@velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via launchctl Persistence
A malicious version of the @velora-dex/sdk npm package was published, delivering an architecture-aware macOS backdoor that activates on import with no visible indicators. The attack occurred at the registry level without repository commits or install hooks.
npmCompromised package - activecritical
axios Compromised on npm - Malicious Versions Drop Remote Access Trojan
A maintainer account for the widely-used axios npm package was compromised and used to publish poisoned versions 1.14.1 and 0.30.4. The malicious releases contained a hidden dependency that drops a cross-platform remote access trojan (RAT).
UNC1069npmAccount takeoverCompromised package - containedhigh
10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions
TeamPCP compromised 76 Trivy version tags on GitHub Actions in an overnight attack, followed by a similar KICS compromise using the same methodology. The attacks targeted credential exfiltration through malicious GitHub Actions.
TeamPCPOtherContainer registryCompromised packageAccount takeover - resolvedcritical
Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest npm Supply Chain Attack
StepSecurity detected a compromise of axios, described as the largest npm supply chain attack on a single package by download count. A state-sponsored threat actor is reported to have actively suppressed warnings by deleting GitHub issues. Detection occurred before public disclosure.
UNC1069npmCompromised packageMalicious maintainer - containedhigh
Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw
Version 2.3.0 of the npm package cline was found to silently install OpenClaw, a malicious payload. The attack was detected and the incident is contained.
npmCompromised package - activecritical
Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor
Three IoliteLabs VSCode extensions (solidity-macos, solidity-windows, solidity-linux) containing obfuscated backdoors targeting Solidity and Web3 developers across Windows, macOS, and Linux. The backdoors download remote payloads and establish persistence mechanisms on infected systems.
Container registryOtherCompromised packageMalicious maintainer - containedcritical
TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package
On March 27, 2026, TeamPCP injected a WAV steganography-based credential stealer into two releases of the telnyx Python SDK on PyPI. The group was identified by shared cryptographic signatures and exfiltration methods matching their earlier litellm compromise.
TeamPCPPyPICompromised package - containedcritical
litellm: Credential Stealer Hidden in PyPI Wheel
A critical supply chain compromise in litellm==1.82.8 on PyPI was identified on March 24, 2026. The malicious PyPI wheel contains a credential stealer hidden in a litellm_init.pth file that executes during package initialization.
TeamPCPPyPICompromised package - containedcritical
Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack
On March 19, 2026, threat actors attributed to "TeamPCP" injected credential-stealing malware into Aqua Security's Trivy scanner and related GitHub Actions. The compromise affected the supply chain of a widely-used container security tool, potentially exposing credentials and secrets in CI/CD environments.
TeamPCPContainer registryOtherCompromised packageMalicious commit - containedcritical
bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys
bittensor-wallet 4.0.2 was published to PyPI on March 17, 2026 with a backdoor that exfiltrates private keys. The compromised package remained available for approximately 48 hours before being yanked from the repository.
PyPICompromised package - containedhigh
Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Downloads Compromised
Malicious releases were discovered in two popular React Native npm packages—react-native-international-phone-number and react-native-country-select—affecting packages with 130K+ monthly downloads combined. StepSecurity detected and reported the compromise on March 16, 2026, and immediately notified maintainers and the community.
ForceMemonpmCompromised package - activecritical
Malware in ulid-os
Malware in ulid-os Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside en
npmCompromised package - activecritical
Malware in utils-mf
Malware in utils-mf Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside e
npmCompromised package - activecritical
Malware in react-ui-polyfills
Malware in react-ui-polyfills Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an
npmCompromised package - activecritical
Malware in glyphr
Malware in glyphr Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside ent
npmCompromised package - activecritical
Malware in reactvora
Malware in reactvora Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside
npmCompromised package - activecritical
Malware in @jagreehal/workflow
Malware in @jagreehal/workflow Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to a
MiasmanpmCompromised package - activecritical
Malware in autotel-terminal
Malware in autotel-terminal Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an o
MiasmanpmCompromised package - activecritical
Withdrawn Advisory: Malware in supabase
Withdrawn Advisory: Malware in supabase ### Withdrawn Advisory This advisory has been withdrawn because the malware detection was a false positive. This link is maintained to preserve external references. ### Original Description Any computer that has this package installed or running should be considered fully comprom
npmCompromised package - activecritical
Malware in nodemon-pack
Malware in nodemon-pack Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsi
npmCompromised package - activecritical
Malware in webpack-json
Malware in webpack-json Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsi
npmCompromised package - activecritical
Malware in nodemon-webpatch
Malware in nodemon-webpatch Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an o
npmCompromised package - activecritical
Malware in chai-midpatch
Malware in chai-midpatch Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outs
npmCompromised package - activecritical
Malware in chai-parse
Malware in chai-parse Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside
npmCompromised package - activecritical
Malware in @redhat-cloud-services/frontend-components-testing
Malware in @redhat-cloud-services/frontend-components-testing Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the co
MiasmanpmCompromised package - activecritical
Malware in @ewfewfewf/testhackerrr
Malware in @ewfewfewf/testhackerrr Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given
npmCompromised package - activecritical
Malware in @osamdefeirrighs/testhackfrrferrr
Malware in @osamdefeirrighs/testhackfrrferrr Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have b
npmCompromised package - activecritical
Malware in @pcldpvkoewpogw/testhacker
Malware in @pcldpvkoewpogw/testhacker Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been giv
npmCompromised package - activecritical
Malware in to-cms
Malware in to-cms Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside ent
npmCompromised package - activecritical
Malware in chainix
Malware in chainix Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside en
npmCompromised package - activecritical
Malware in chai-as-minted
Malware in chai-as-minted Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an out
npmCompromised package - activecritical
Malware in @tmecontinue/cli
Malware in @tmecontinue/cli Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an o
npmCompromised package - activecritical
Malware in collected-forms-embed-js
Malware in collected-forms-embed-js Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given
npmCompromised package - activecritical
Malware in cms-github
Malware in cms-github Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside
npmCompromised package - activecritical
Malware in cms-storehub
Malware in cms-storehub Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsi
npmCompromised package - activecritical
Malware in shopifyto-cms
Malware in shopifyto-cms Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outs
npmCompromised package - activecritical
Malware in @antoncallahan/aws-user-helper
Malware in @antoncallahan/aws-user-helper Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been
npmCompromised package - activecritical
Malware in json-to-simple-graphql-schema
Malware in json-to-simple-graphql-schema Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been
npmCompromised package - activecritical
Malware in @redhat-cloud-services/entitlements-client
Malware in @redhat-cloud-services/entitlements-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m
MiasmanpmCompromised package - activecritical
Malware in @chat-template/auth
Malware in @chat-template/auth Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to a
npmCompromised package - activecritical
Malware in cms-helpgit
Malware in cms-helpgit Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsid
npmCompromised package - activecritical
Malware in @redhat-cloud-services/sources-client
Malware in @redhat-cloud-services/sources-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may ha
MiasmanpmCompromised package - activecritical
Malware in @redhat-cloud-services/frontend-components-remediations
Malware in @redhat-cloud-services/frontend-components-remediations Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of t
MiasmanpmCompromised package - activecritical
Malware in peertube-plugin-google-analytics-js
Malware in peertube-plugin-google-analytics-js Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have
npmCompromised package - activecritical
Malware in @redhat-cloud-services/rbac-client
Malware in @redhat-cloud-services/rbac-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have
MiasmanpmCompromised package - activecritical
Malware in @redhat-cloud-services/topological-inventory-client
Malware in @redhat-cloud-services/topological-inventory-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the c
MiasmanpmCompromised package - activecritical
Malware in @tmecontinue/claude
Malware in @tmecontinue/claude Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to a
npmAI agents & skillsCompromised package - activecritical
Malware in xarc-webpack-cli
Malware in xarc-webpack-cli Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an o
npmCompromised package - activecritical
Malware in @redhat-cloud-services/quickstarts-client
Malware in @redhat-cloud-services/quickstarts-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer ma
MiasmanpmCompromised package - activecritical
Malware in @redhat-cloud-services/integrations-client
Malware in @redhat-cloud-services/integrations-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m
MiasmanpmCompromised package - activecritical
Malware in randomlogs
Malware in randomlogs Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside
npmCompromised package - activecritical
Malware in @redhat-cloud-services/frontend-components-config
Malware in @redhat-cloud-services/frontend-components-config Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the com
MiasmanpmCompromised package - activecritical
Malware in loading-session
Malware in loading-session Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an ou
npmCompromised package - activecritical
Malware in motion-tool
Malware in motion-tool Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsid
npmCompromised package - activecritical
Malware in jingmeideshishi
Malware in jingmeideshishi Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an ou
npmCompromised package - activecritical
Malware in @redhat-cloud-services/eslint-config-redhat-cloud-services
Malware in @redhat-cloud-services/eslint-config-redhat-cloud-services Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control o
MiasmanpmCompromised package - activecritical
Malware in @redhat-cloud-services/types
Malware in @redhat-cloud-services/types Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been g
MiasmanpmCompromised package - activecritical
Malware in @redhat-cloud-services/frontend-components
Malware in @redhat-cloud-services/frontend-components Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m
MiasmanpmCompromised package - activecritical
Malware in nemo-reporter
Malware in nemo-reporter Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outs
npmCompromised package - activecritical
Malware in @redhat-cloud-services/rule-components
Malware in @redhat-cloud-services/rule-components Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may h
MiasmanpmCompromised package - activecritical
Malware in audit-logsss
Malware in audit-logsss Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsi
npmCompromised package - activecritical
Malware in @redhat-cloud-services/hcc-feo-mcp
Malware in @redhat-cloud-services/hcc-feo-mcp Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have
MiasmanpmAI agents & skillsCompromised package - activecritical
Malware in @redhat-cloud-services/frontend-components-config-utilities
Malware in @redhat-cloud-services/frontend-components-config-utilities Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control
MiasmanpmCompromised package - activecritical
Malware in @redhat-cloud-services/chrome
Malware in @redhat-cloud-services/chrome Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been
MiasmanpmCompromised package - activecritical
Malware in @t-in-one/add_application_tid
Malware in @t-in-one/add_application_tid Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been
npmCompromised package - activecritical
Malware in @t-in-one/get_application_hid
Malware in @t-in-one/get_application_hid Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been
npmCompromised package - activecritical
Malware in @t-in-one/add_application
Malware in @t-in-one/add_application Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been give
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/ml-ai-agents-agent-system
Malware in @cloudplatform-single-spa/ml-ai-agents-agent-system Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the c
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/security-groups
Malware in @cloudplatform-single-spa/security-groups Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer ma
npmCompromised package - activecritical
Withdrawn Advisory: Malware in puppeteer
Withdrawn Advisory: Malware in puppeteer ### Withdrawn Advisory This advisory has been withdrawn because the malicious package detection was a false positive. This link is maintained to preserve external references. ### Original Description Any computer that has this package installed or running should be considered fu
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/floating-ips
Malware in @cloudplatform-single-spa/floating-ips Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may h
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/enterprise
Malware in @cloudplatform-single-spa/enterprise Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may hav
npmCompromised package - activecritical
Malware in @t-in-one/prefill_bundle_data_token
Malware in @t-in-one/prefill_bundle_data_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/business-solutions
Malware in @cloudplatform-single-spa/business-solutions Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer
npmCompromised package - activecritical
Malware in @t-in-one/send_add_application
Malware in @t-in-one/send_add_application Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been
npmCompromised package - activecritical
Malware in @t-in-one/prefill_credit_data_token
Malware in @t-in-one/prefill_credit_data_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have
npmCompromised package - activecritical
Malware in @t-in-one/only_difference_payload
Malware in @t-in-one/only_difference_payload Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have b
npmCompromised package - activecritical
Malware in midoss
Malware in midoss Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside ent
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/dataplatform-trino
Malware in @cloudplatform-single-spa/dataplatform-trino Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer
npmCompromised package - activecritical
Malware in @t-in-one/prefill_transformers_data_token
Malware in @t-in-one/prefill_transformers_data_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer ma
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/logaas
Malware in @cloudplatform-single-spa/logaas Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have be
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/base-static-page
Malware in @cloudplatform-single-spa/base-static-page Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m
npmCompromised package - activecritical
Malware in @t-in-one/safe_local_storage_token
Malware in @t-in-one/safe_local_storage_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have
npmCompromised package - activecritical
Malware in power-platform-playwright-toolkit
Malware in power-platform-playwright-toolkit Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have b
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/administration
Malware in @cloudplatform-single-spa/administration Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/cnapp-ui
Malware in @cloudplatform-single-spa/cnapp-ui Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/cp-api-gw
Malware in @cloudplatform-single-spa/cp-api-gw Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/dataplatform-metastore
Malware in @cloudplatform-single-spa/dataplatform-metastore Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the comp
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/employees
Malware in @cloudplatform-single-spa/employees Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have
npmCompromised package - activecritical
Malware in @sber-ecom-core/sberpay-widget
Malware in @sber-ecom-core/sberpay-widget Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been
npmCompromised package - activecritical
Malware in customerdigital-service-lib
Malware in customerdigital-service-lib Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been gi
npmCompromised package - activecritical
Malware in @capibar.chat/ui-kit
Malware in @capibar.chat/ui-kit Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to
npmCompromised package - activecritical
Malware in @t-in-one/form_product_token
Malware in @t-in-one/form_product_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been g
npmCompromised package - activecritical
Malware in @t-in-one/application_id_storage_key_token
Malware in @t-in-one/application_id_storage_key_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/ml-ai-agents-agent
Malware in @cloudplatform-single-spa/ml-ai-agents-agent Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/svp-baas
Malware in @cloudplatform-single-spa/svp-baas Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/cloud-dns
Malware in @cloudplatform-single-spa/cloud-dns Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/dataplatform
Malware in @cloudplatform-single-spa/dataplatform Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may h
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/vpn
Malware in @cloudplatform-single-spa/vpn Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been
npmCompromised package - activecritical
Malware in @t-in-one/save_application_hid_to_storage
Malware in @t-in-one/save_application_hid_to_storage Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer ma
npmCompromised package - activecritical
Malware in @t-in-one/restore_application_hid_from_storage
Malware in @t-in-one/restore_application_hid_from_storage Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the comput
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/monitoring
Malware in @cloudplatform-single-spa/monitoring Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may hav
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/marketplace-gigachat
Malware in @cloudplatform-single-spa/marketplace-gigachat Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the comput
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/svp-s3-storage
Malware in @cloudplatform-single-spa/svp-s3-storage Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may
npmCompromised package - activecritical
Malware in @t-in-one/add_application_service_token
Malware in @t-in-one/add_application_service_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/ssh-keys
Malware in @cloudplatform-single-spa/ssh-keys Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/support
Malware in @cloudplatform-single-spa/support Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have b
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/arenadata-db
Malware in @cloudplatform-single-spa/arenadata-db Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may h
npmCompromised package - activecritical
Malware in @t-in-one/add_app_middleware_token
Malware in @t-in-one/add_app_middleware_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/svp-interfaces
Malware in @cloudplatform-single-spa/svp-interfaces Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may
npmCompromised package - activecritical
Malware in @cloudplatform-single-spa/datagrid
Malware in @cloudplatform-single-spa/datagrid Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have
npmCompromised package