Skip to content
supplychainattack.orgSupply chain attack incident catalog

Compromised package incidents

2390 confirmed incidents involving the compromised-package technique.

  1. activecritical

    Malware in litespeed-cache

    Malware discovered in the npm package litespeed-cache. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  2. containedcritical

    Malware in n8n-nodes-trust-me-im-totally-safe

    Malware was discovered in the npm package n8n-nodes-trust-me-im-totally-safe, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  3. resolvedcritical

    Malicious code in test2221 (npm)

    The npm package test2221 version 2.2.4 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.

    npmCompromised package
  4. activecritical

    Malware in @ai-plus/de-agent

    The npm package @ai-plus/de-agent contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmAI agents & skillsCompromised package
  5. activecritical

    Malware in @ai-plus/de-agent-sdk

    Malware discovered in the npm package @ai-plus/de-agent-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  6. containedcritical

    Malware in feedback-ai-sdk

    Malware was discovered in the npm package feedback-ai-sdk. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  7. activecritical

    Malware in @zannstore/baileys

    Malware was discovered in the npm package @zannstore/baileys. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  8. containedcritical

    Malware in stake-math

    The npm package stake-math was found to contain malware. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  9. containedcritical

    Malware in data-parser-utils

    Malware was discovered in the npm package data-parser-utils. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  10. activecritical

    Malware in @peptide-unit/peptide-modify

    Malware discovered in the npm package @peptide-unit/peptide-modify. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  11. containedcritical

    Malware in flight-compare-analyzer

    Malware was discovered in the npm package flight-compare-analyzer. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  12. activecritical

    Malware in def-open-client

    The npm package def-open-client contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  13. containedcritical

    Malware in uniapi-bridge

    Malware was discovered in the npm package uniapi-bridge, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  14. containedcritical

    Malware in aone-cloud-cli

    Malware was discovered in the npm package aone-cloud-cli, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  15. containedcritical

    Malware in ts-precision

    Malware was discovered in the npm package ts-precision, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.

    npmCompromised package
  16. containedcritical

    Malware in lwp-web-client

    The npm package lwp-web-client was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  17. activecritical

    Malware in @ai-agent-node/agent-node

    Malware discovered in the npm package @ai-agent-node/agent-node. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  18. activecritical

    Malware in @ai-agent-node/nodesql

    The npm package @ai-agent-node/nodesql contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmAI agents & skillsCompromised package
  19. activecritical

    Malware in @ai-agent-node/createnode

    Malware discovered in the npm package @ai-agent-node/createnode. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  20. resolvedcritical

    Malware in colder-cli

    The npm package colder-cli contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  21. activecritical

    Malware in lzd-unified-station-sdk

    Malware discovered in the npm package lzd-unified-station-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  22. containedcritical

    Malware in test-skill-zip

    Malware was discovered in the npm package test-skill-zip. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  23. activecritical

    Malware in @peptide-unit/js-unimode

    Malware discovered in the npm package @peptide-unit/js-unimode. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  24. containedcritical

    Malware in poly-kelly

    Malware was discovered in the npm package poly-kelly. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.

    npmCompromised package
  25. containedcritical

    Malware in eslintcmd

    The npm package eslintcmd was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-73c6-pgjj-9v82 was published on 2026-07-29.

    npmCompromised package
  26. containedcritical

    Malware in ts-bn-proto

    Malware was discovered in the npm package ts-bn-proto. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  27. containedcritical

    Malware in @bowozzz/baileys

    The npm package @bowozzz/baileys contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  28. containedcritical

    Malware in polymarket-risk-manager

    Malware was discovered in the npm package polymarket-risk-manager, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  29. containedcritical

    Malicious code in @finxsecdemo/utils (npm)

    The npm package @finxsecdemo/utils version 1.0.2 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  30. containedcritical

    Malware in zer0code

    The npm package zer0code was found to contain malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  31. activecritical

    Malware in @omniwatch-wick/cli

    Malware discovered in the npm package @omniwatch-wick/cli. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  32. activecritical

    Malware in chain-manager

    Malware discovered in the npm package chain-manager. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  33. activecritical

    Malware in chain-analyze

    Malware discovered in the npm package chain-analyze. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  34. containedcritical

    Malicious code in @mypwn/hawkeye (npm)

    The npm package @mypwn/hawkeye version 99.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.

    npmCompromised package
  35. containedcritical

    Malicious code in blots (npm)

    The npm package 'blots' version 2.1.0 was identified by the OpenSSF Package Analysis project as containing malicious code that executes commands associated with malicious behavior. The package has been flagged in the OpenSSF malicious packages database.

    npmCompromised package
  36. containedcritical

    Malicious code in toll_free (npm)

    The npm package toll_free version 1.0.1 was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.

    npmCompromised package
  37. containedcritical

    Malware in open-worker-cli

    Malware was discovered in the npm package open-worker-cli. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  38. containedcritical

    Malicious code in num-format-helper (npm)

    The npm package num-format-helper version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  39. resolvedcritical

    Malicious code in bianira-ui (npm)

    The npm package bianira-ui contained malicious code that executed on import, enabling remote code execution via a blockchain-based dead-drop C2 mechanism. The payload used unicode escapes to evade detection and dynamically resolved C2 endpoints through Ethereum transactions.

    npmCompromised package
  40. resolvedcritical

    Malicious code in cfgzen (PyPI)

    Malicious code was discovered in the cfgzen PyPI package, embedded in a native module that functions as an infostealer. The malicious code downloads and executes an encrypted remote executable, with capabilities to exfiltrate environment variables and detect sandbox environments. The package has been identified as part of campaign 2026-07-cfgzen.

    2026 07 CfgzenPyPICompromised package
  41. activecritical

    Malware in @vaultflow/create-flow

    Malware discovered in the npm package @vaultflow/create-flow. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  42. activecritical

    Malware in @joyfill/components

    Malware was discovered in the npm package @joyfill/components. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  43. activecritical

    Malware in @joyfill/layouts

    Malware was discovered in the npm package @joyfill/layouts. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  44. containedcritical

    Malicious code in @apexfnd/apex (npm)

    The npm package @apexfnd/apex contained a malicious postinstall script that executed remote code at install time. On macOS, it prompted for administrator credentials and executed a shell script as root; on all platforms, it downloaded and executed an unsigned binary from attacker-controlled infrastructure.

    npmCompromised package
  45. containedcritical

    Malicious code in @crbrc/xbt (npm)

    The npm package @crbrc/xbt contains malicious code that exfiltrates OxaPay payment-gateway secrets and host metadata to a hardcoded attacker-controlled IP address, establishes a reverse TCP proxy tunnel, and allows remote process termination. The malicious behavior is conditionally activated only when all project source files import the companion package @crb/xbr.

    npmCompromised packageMalicious commit
  46. resolvedcritical

    Malicious code in ethers-secure (npm)

    The npm package ethers-secure, which mimics the popular ethers library, contained malicious code that exfiltrated Ethereum private keys to an attacker-controlled server (enjbyg3xk8l.x.pipedream.net) whenever its wallet API was used. The package was identified by Amazon Inspector and credited to the OpenSSF malicious-packages project.

    npmCompromised packageTyposquatting
  47. containedcritical

    Malicious code in api-rust-sdk (npm)

    The npm package api-rust-sdk contained malicious code in its postinstall hook that harvested credentials (Solana keypairs, Rust configs, dotenv secrets), exfiltrated files matching attacker-defined patterns, and installed a persistent SSH backdoor on infected systems.

    npmCompromised package
  48. containedcritical

    Malicious code in color-convert-helper (npm)

    The npm package color-convert-helper contained malicious code in its postinstall.js script that harvested cloud credentials, IAM tokens, and environment variables from infected systems, then exfiltrated the data to an attacker-controlled OAST domain. The package also performed internal network reconnaissance.

    npmCompromised package
  49. resolvedcritical

    Malicious code in react-puller (npm)

    The npm package react-puller contained malicious code in its postinstall hook that downloads and executes Windows binaries from a hardcoded IP endpoint, establishing persistence via Windows registry autostart.

    npmCompromised package
  50. containedcritical

    Malicious code in api-node-sdk (npm)

    The npm package api-node-sdk contained malicious code in its postinstall hook that harvested secrets, established persistent SSH access, and exfiltrated files from infected systems. The package executed attacker-controlled workflows to scan for and steal configuration files, keypairs, and environment variables, then installed SSH backdoors and enabled remote access.

    npmCompromised package
  51. resolvedcritical

    Malicious code in tidal-embed-player (npm)

    The npm package tidal-embed-player contained malicious code that executed on installation, collecting host identifiers and system files, then exfiltrating the data to an attacker-controlled domain. The package had no legitimate functionality despite its name suggesting a Tidal media player.

    npmCompromised package
  52. resolvedcritical

    Malicious code in streak-core-math (npm)

    The npm package streak-core-math contained malicious code that downloads and executes a binary on Windows developer machines. The payload fetches a ZIP file from Backblaze B2, unpacks it, and establishes persistence via a VBS launcher in the Windows Startup folder.

    npmCompromised package
  53. containedcritical

    Malicious code in karpatkey (PyPI)

    The karpatkey package on PyPI contained malicious code that exfiltrated sensitive credentials and data from infected systems. Upon import, the package spawned a background daemon thread that collected SSH keys, AWS/GCP credentials, kubeconfig, cryptocurrency wallets, and other secrets, then transmitted them via HTTP to hardcoded IP addresses.

    PyPICompromised packageMalicious commit
  54. containedcritical

    Malicious code in mrmustard (PyPI)

    A malicious version of the mrmustard package was published to PyPI containing code that exfiltrates SSH keys, AWS credentials, Kubernetes config, environment variables, and system identifiers to a remote endpoint. The payload includes multiple persistence mechanisms that survive package uninstallation.

    PyPICompromised package
  55. containedcritical

    Malicious code in karpatkit (PyPI)

    The karpatkit package on PyPI contained malicious code that exfiltrated sensitive credentials and secrets on import. The package spawned a daemon thread collecting environment variables, cloud credentials, SSH keys, Kubernetes tokens, cryptocurrency wallets, and shell histories, then transmitted them via HTTP to hardcoded IP addresses.

    PyPICompromised packageMalicious commit
  56. resolvedcritical

    Malicious code in xerohub-discord-voice-v3 (npm)

    The npm package xerohub-discord-voice-v3 contained malicious code that exfiltrated Discord user authentication tokens to a hardcoded webhook URL controlled by the package author. The startVoiceJoiner() function unconditionally sent raw tokens, usernames, guild IDs, and voice channel IDs to discord.com/api/webhooks/1528726419046404196 before executing any legitimate voice functionality.

    npmCompromised packageMalicious maintainer
  57. containedcritical

    Malicious code in @ai_/autoprefixers (npm)

    @ai_/autoprefixers is a typosquat of the legitimate autoprefixer package that executes arbitrary attacker-controlled shell commands on installation. The malicious code fetches encrypted payloads from remote C2 servers and decrypts them using a hardcoded key suffix before execution via child_process.exec.

    npmTyposquattingCompromised package
  58. containedcritical

    Malicious code in app-soda-layer (npm)

    The npm package app-soda-layer contained malicious code in its postinstall hook that exfiltrated sensitive files, enumerated the filesystem, and injected SSH keys for persistent remote access. The package was identified by Amazon Inspector and credited to OpenSSF's malicious-packages repository.

    npmCompromised package
  59. containedcritical

    Malicious code in dev-helper-bg (PyPI)

    The PyPI package dev-helper-bg contained malicious code that executed arbitrary commands on import. The package decrypted and executed remotely-controlled code fetched from an external endpoint, and spawned a Telegram bot for command and control.

    2026 07 Make HelperPyPICompromised packageMalicious commit
  60. resolvedcritical

    Malicious code in kordyn (npm)

    The npm package kordyn contained malicious code: a base64-encoded Windows PE64 executable embedded in its main entry point (index.mjs). When imported in a Linux WSL environment, the module writes the binary to the Windows Startup folder, achieving persistence and code execution on the developer's Windows host.

    npmCompromised package
  61. containedcritical

    Malicious code in app-sima-layer (npm)

    The npm package app-sima-layer contained malicious code in its postinstall script that performed coordinated attacks: installing SSH backdoors on Linux, stealing wallet and configuration files, and harvesting files matching attacker-controlled patterns from the host system.

    npmCompromised package
  62. resolvedcritical

    Malicious code in app-sim-layer (npm)

    The npm package app-sim-layer contained malicious code in a postinstall hook that exfiltrated sensitive files (Solana keypairs, API keys, credentials), enumerated the user's filesystem, and on Linux granted remote SSH access to attacker infrastructure at 95.216.118.146.

    npmCompromised packageMalicious commit
  63. containedcritical

    Malicious code in @yancyyu/agentcli (npm)

    The npm package @yancyyu/agentcli contains malicious code that extracts OAuth credentials and API keys for Lark/Feishu from the system keychain (macOS) and credential store (Windows), then exfiltrates them to a hardcoded remote IP address over plaintext HTTP. A persistent launchd agent ensures the exfiltration loop survives reboots.

    npmAI agents & skillsCompromised packageMalicious commit
  64. containedcritical

    Malicious code in chain-analyze (npm)

    The npm package chain-analyze contained malicious code that executed arbitrary Node.js commands on installation. The package impersonated the official Theta blockchain SDK and used a split-package design with a dependency (chain-manager) to hide encrypted payload from scanners.

    npmCompromised packageTyposquatting
  65. resolvedcritical

    Malicious code in node-array-plus (npm)

    node-array-plus, an npm package with no legitimate functionality, contained heavily obfuscated malicious code that downloads, decrypts, and executes remote code on installation. The package was identified and reported by OpenSSF's malicious-packages project.

    npmCompromised package
  66. resolvedcritical

    Malicious code in fluid-type-ui (npm)

    fluid-type-ui@2.0.8 on npm contains hidden malicious code that executes arbitrary attacker-controlled code on module load via an Ethereum-based command-and-control mechanism. The code queries Ethereum JSON-RPC endpoints for instructions embedded in blockchain transactions, making it resistant to traditional takedown.

    npmCompromised package
  67. containedcritical

    Malicious code in json-schema-inspector (npm)

    The npm package json-schema-inspector contained malicious code that performed remote code execution on installation. The package advertised itself as a JSON/XML schema validator but included a trigger routine that fetched and executed attacker-controlled payloads from a remote manifest.

    npmCompromised packageMalicious commit
  68. containedcritical

    Malicious code in parallely (npm)

    The npm package parallely contains malicious code that impersonates the legitimate concurrently package. When invoked, it executes a dropper that downloads and runs platform-specific payloads after anti-analysis checks.

    npmCompromised packageTyposquatting
  69. containedcritical

    Malicious code in app-svm-layer (npm)

    The npm package app-svm-layer contained malicious code in its postinstall script that executed automatically on install, establishing unauthorized SSH access, exfiltrating credentials and configuration files, and scanning for sensitive data across the host system.

    npmCompromised package
  70. resolvedcritical

    Malicious code in basic-vite (npm)

    The npm package basic-vite contained malicious code that executed automatically during installation, collecting and exfiltrating sensitive host identity data and system files to an attacker-controlled server.

    npmCompromised package
  71. resolvedcritical

    Malicious code in jobber-app-template-react (npm)

    The npm package jobber-app-template-react contained malicious code in its preinstall hook that executed automatically on npm install. The script performed host reconnaissance and exfiltrated sensitive system information to a Burp Collaborator domain.

    npmCompromised package
  72. resolvedcritical

    Malicious code in array-node-utils (npm)

    The npm package array-node-utils contained malicious code that fetches, decrypts, and executes arbitrary code on installation. The package's declared purpose (array utilities) bore no relationship to the shipped obfuscated payload.

    npmCompromised package
  73. containedcritical

    Malicious code in streak-core-lib (npm)

    streak-core-lib@1.0.0 on npm contains malicious code that drops a Windows PE executable to the Startup folder on installation, achieving persistent code execution. The package falsely advertises itself as a day-math primitives library and executes the payload automatically on import without user interaction.

    npmCompromised package
  74. resolvedcritical

    Malicious code in triage_bot_using_sdkv3 (npm)

    The npm package triage_bot_using_sdkv3 contained malicious code that executed during installation, exfiltrating system information and local files to an attacker-controlled endpoint. The package registered a preinstall hook that collected hostname, user information, DNS configuration, and sensitive files like /etc/passwd and /etc/hosts.

    npmCompromised package
  75. resolvedcritical

    Malicious code in xerohub-discord-voice-v2 (npm)

    The npm package xerohub-discord-voice-v2 contained malicious code that silently exfiltrated Discord user tokens and server/channel IDs to an attacker-controlled webhook URL when users invoked the advertised `startVoiceJoiner(config)` API with their credentials.

    npmCompromised package
  76. containedcritical

    Malicious code in text-line-parser (npm)

    The npm package text-line-parser contained malicious code in its postinstall.js that collected system information, environment variables (including CI tokens and cloud credentials), and exfiltrated them to a Burp Collaborator domain. The package advertised itself as a text-parsing utility but shipped only stub functions, consistent with a typosquat/decoy supply-chain attack.

    npmCompromised packageTyposquatting
  77. resolvedcritical

    Malicious code in rollup-runtime-core-polyfills (npm)

    The npm package rollup-runtime-core-polyfills contained malicious code that impersonated a legitimate rollup polyfill plugin. On every import/require, it decoded and executed a shell command to install an attacker-controlled package (svgcraft-core) and executed code from it, affecting any build system that consumed this package.

    npmCompromised packageTyposquatting
  78. containedcritical

    Malicious code in streak-daily-lib (npm)

    The npm package streak-daily-lib contained malicious code that executes on import, downloads and executes binaries from attacker-controlled infrastructure, and establishes persistence on Windows hosts via WSL. The package was published with a benign stated purpose (calendar/streak math) but implements a sophisticated supply chain attack with cross-platform capabilities.

    npmCompromised package
  79. containedcritical

    Malicious code in sigchain-js (npm)

    Malicious code was injected into the published npm package sigchain-js, executing arbitrary code on installation via DES-decrypted payloads from companion packages thedata and tchain-api. The attack also involved typosquatting axios to version 1.18.1, which does not exist in legitimate release history.

    npmCompromised packageDependency confusionTyposquatting
  80. containedcritical

    Malicious code in simple-probe-utils (npm)

    The npm package simple-probe-utils contained malicious postinstall code that harvested cloud provider credentials (AWS IAM, Tencent, Aliyun, GCP, Azure) and exfiltrated them to an attacker-controlled domain. The package was masqueraded as a string formatting utility but contained only credential-stealing functionality.

    npmCompromised package
  81. containedcritical

    Malicious code in govapkg (PyPI)

    govapkg, a malicious PyPI package, downloads and executes a hidden binary on first use, establishing persistence via a systemd desktop autostart entry. The package obfuscates its malicious behavior through base64-encoded URLs and downloads from unverified external sources.

    PyPICompromised packageMalicious commit
  82. resolvedcritical

    Malicious code in vtranalytic (PyPI)

    The vtranalytic package on PyPI contained malicious code implementing a Telegram-bot-driven remote administration tool that provides full system control to an attacker holding the configured bot token. The package exfiltrates credentials, SSH keys, and arbitrary files via Telegram API, and executes arbitrary shell commands through a documented `run` command.

    PyPICompromised packageMalicious maintainer
  83. containedcritical

    Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan

    Malicious beta versions of npm packages @joyfill/components and @joyfill/layouts were published containing an obfuscated remote access trojan and credential stealer. The compromise affected developers who installed these packages during the malicious release window.

    npmCompromised package
  84. containedcritical

    Malware in postcss-motion-utils

    Malware was discovered in the npm package postcss-motion-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  85. containedcritical

    Malware in cloud-config-fetcher

    Malware was discovered in the npm package cloud-config-fetcher. Any system with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  86. resolvedcritical

    Malware in aone-kit

    The npm package aone-kit contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  87. containedcritical

    Malware in local-config-parser

    Malware was discovered in the npm package local-config-parser. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  88. containedcritical

    Malware in smart-config-manager

    Malware was discovered in the npm package smart-config-manager. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  89. containedcritical

    Malware in aone-kit-cli

    Malware was discovered in the npm package aone-kit-cli, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  90. resolvedcritical

    Malware in aone-sandbox

    The npm package aone-sandbox contained malware that compromised any system where it was installed or executed. The package granted outside entities full control of affected computers.

    npmCompromised package
  91. containedcritical

    Malware in lib-mtop

    Malware was discovered in the npm package lib-mtop, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  92. containedcritical

    Malicious code in json-to-table-util (npm)

    The npm package json-to-table-util version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  93. containedcritical

    Malicious code in string-format-kit (npm)

    The npm package string-format-kit version 1.0.2 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  94. containedcritical

    Malicious code in date-sanitize-helper (npm)

    The npm package 'date-sanitize-helper' version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  95. activecritical

    Malware in @vaultflow/update-flow

    Malware was discovered in the npm package @vaultflow/update-flow. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  96. resolvedcritical

    Malicious code in korvica (npm)

    The npm package korvica contained malicious code that, on import in non-production Linux/WSL environments, fetches and executes an unsigned binary to the Windows Startup folder. The payload is obfuscated using single-letter variables and template literals to evade detection.

    npmCompromised package
  97. containedcritical

    Malicious code in lib-streak-math (npm)

    The npm package lib-streak-math contained obfuscated malicious code that executes on import, downloading and executing a remote payload. On Windows, it establishes persistence via startup folder; on Linux, it spawns a detached background service.

    npmCompromised package
  98. containedcritical

    Malicious code in array-sort-helper (npm)

    The npm package array-sort-helper version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  99. containedcritical

    Malicious code in @antv/gi-assets-galaxybase (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-galaxybase, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  100. resolvedcritical

    Malicious code in truffle-js (npm)

    The npm package truffle-js (version 2.0.0) contained malicious code that executed arbitrary remote content via curl during installation. The package name resembles the legitimate 'truffle' Ethereum toolkit, consistent with a typosquatting attack.

    npmCompromised packageTyposquatting
  101. containedcritical

    Malicious code in amapcn (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including amapcn, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  102. activecritical

    Malware in motion-forge-css

    The npm package motion-forge-css contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  103. containedcritical

    Malicious code in ethers-common (npm)

    The npm package ethers-common v1.0.0 contained malicious code that executed arbitrary commands during installation via a postinstall hook. The package impersonated the legitimate ethers Web3 library and used a base64-obfuscated URL to fetch and execute attacker-controlled code over plain HTTP.

    npmCompromised packageTyposquatting
  104. resolvedcritical

    Malicious code in cdp-core (npm)

    The npm package cdp-core contained malicious code (cdp_inject.js) designed to harvest system information and credentials, then exfiltrate them over HTTPS to a hardcoded remote server. The package provided no legitimate functionality and was identified by OpenSSF's malicious-packages project.

    npmCompromised package
  105. containedcritical

    Malicious code in paysafe-gbp-virtual-assistant-lib-fe (npm)

    The npm package paysafe-gbp-virtual-assistant-lib-fe version 2.0.4 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands associated with malicious behavior.

    npmCompromised package
  106. containedcritical

    Malicious code in @antv/gi-assets-janusgraph (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-assets-janusgraph, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  107. containedcritical

    Malicious code in ethers-io (npm)

    The npm package ethers-io (version 2.0.0) contained malicious code that executed arbitrary shell commands during installation via a postinstall script. The package impersonates the legitimate ethers.js ecosystem and fetches and executes attacker-controlled code from a bare IPv4 address over unencrypted HTTP.

    npmCompromised packageTyposquatting
  108. containedcritical

    Malicious code in @antv/gi-cli (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-cli, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  109. containedcritical

    Malicious code in @antv/react-g (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/react-g, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  110. containedcritical

    Malicious code in @antv/l7-mini (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/l7-mini, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludTeamPCPnpmCompromised packageAccount takeover
  111. containedcritical

    Malicious code in @antv/xflow-diff (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/xflow-diff. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  112. containedcritical

    Malicious code in @antv/gi-assets-tugraph-analytics (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-tugraph-analytics, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  113. resolvedcritical

    Malicious code in request-logger-canary (npm)

    request-logger-canary@1.0.0 on npm contains a malicious preinstall.js script that establishes a reverse shell to 52.74.242.200:8851 when npm install runs, granting remote interactive shell access. The package README falsely claims the payload is dead code in postinstall.js, indicating deliberate obfuscation.

    npmCompromised package
  114. containedcritical

    Malicious code in @antv/github-config-cli (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages in an automated attack. The @antv/github-config-cli package was modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  115. containedcritical

    Malicious code in @antv/gi-theme-antd (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-theme-antd, each injecting a preinstall hook executing an obfuscated Bun script. The attack exfiltrated credentials via GitHub API and established persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  116. containedcritical

    Malicious code in @antv/gi-assets-xlab (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-assets-xlab, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  117. containedcritical

    Malicious code in @tc-core/campus-service (npm)

    The npm package @tc-core/campus-service version 0.0.0-defensive-callback was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  118. containedcritical

    Malicious code in @antv/l7-pass (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/l7-pass, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  119. containedcritical

    Malicious code in @antv/x6-react (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/x6-react, each injecting a preinstall hook that executes an obfuscated Bun script to exfiltrate credentials via GitHub API. The attack also establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmCompromised packageAccount takeover
  120. containedcritical

    Malicious code in @antv/l7-three (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/l7-three, each injecting a preinstall hook that executes an obfuscated Bun script to exfiltrate credentials and establish persistence. The attack targeted AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, and Slack tokens.

    Mini Shai HuludTeamPCPnpmCompromised packageAccount takeover
  121. containedcritical

    Malicious code in @antv/word-scale-chart (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/word-scale-chart, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  122. containedcritical

    Malicious code in vue-template-compiler-plugin (npm)

    A malicious npm package named vue-template-compiler-plugin impersonates the legitimate vue-template-compiler library and contains a full C2 implant. The postinstall hook decodes and executes a remote-access trojan that registers victims to a Cloudflare tunnel C2 server and beacons for commands.

    npmCompromised packageTyposquatting
  123. containedcritical

    Malicious code in chalk-pack (npm)

    A malicious npm package named chalk-pack impersonated the legitimate chalk library and executed a two-stage stealer on install: harvesting npm credentials, environment variables, and cryptocurrency wallet data from browser extensions and local files, exfiltrating to a hardcoded C2 server.

    npmCompromised packageTyposquatting
  124. resolvedcritical

    Malicious code in @webapp-next/store (npm)

    The npm package @webapp-next/store contained malicious code that executed automatically on installation, collecting system and user information and exfiltrating it to an attacker-controlled server. The package had no legitimate functionality and used a dependency-confusion lure with a scope resembling a legitimate namespace.

    npmCompromised packageDependency confusion
  125. resolvedcritical

    Malicious code in cache-poisoning-pwn-demo (npm)

    The npm package cache-poisoning-pwn-demo contains malicious code in its postinstall hook and main entry point that executes platform-specific calculator commands at install-time and import-time without user consent. The package is self-described as a supply-chain attack demonstration, but the delivery mechanism is a fully functional arbitrary-command executor.

    npmCompromised package
  126. containedcritical

    Malicious code in @design-system-coopeuch/web (npm)

    @design-system-coopeuch/web versions 999.0.4 and 999.0.0 on npm contained malicious code implementing a dependency-confusion attack. The package included a preinstall hook that exfiltrated host identifiers (hostname, working directory, user ID, environment variables) to a hardcoded IP address via cleartext HTTP.

    npmDependency confusionCompromised package
  127. containedcritical

    Malicious code in exxpress-tool (npm)

    The npm package exxpress-tool (a one-character typosquat of express) contains malicious postinstall code that harvests npm tokens, git credentials, environment variables, and cryptocurrency wallet seeds from developer machines and CI environments, exfiltrating them to a hardcoded IP endpoint.

    npmCompromised packageTyposquatting
  128. containedcritical

    Malicious code in glob-helper (npm)

    glob-helper@1.0.2 is a malicious typosquat package that executes a postinstall script to steal npm tokens, AWS credentials, GitHub tokens, and cryptocurrency wallet data from developer machines. The stolen data is exfiltrated to a hardcoded C2 server at http://149.28.127.35:8888 over plain HTTP.

    npmTyposquattingCompromised package
  129. containedcritical

    Malicious code in env-threads (npm)

    The npm package env-threads is a typosquat of the legitimate dotenv package that executes arbitrary code hidden in a steganographic JPEG payload when required. The malicious package copies dotenv's README, repository URL, homepage, description, keywords, and API surface, but ships an 82 KB obfuscated main.js that decodes and executes the hidden payload via child_process at module load time.

    npmTyposquattingCompromised package
  130. containedcritical

    Malicious code in nock-helper (npm)

    The npm package nock-helper contained a malicious postinstall script that harvested credentials, API keys, and cryptocurrency wallet data from infected systems. The script exfiltrated npm tokens, environment variables, git credentials, and browser wallet extension data to a hardcoded C2 server.

    npmCompromised packageMalicious commit
  131. containedcritical

    Malicious code in chalk-utils (npm)

    The npm package chalk-utils contained malicious code in its postinstall.js script that steals credentials, cryptocurrency wallet data, and sensitive files from developer machines. The package masquerades as a chalk utility while executing a credential and cryptocurrency stealer on installation.

    npmCompromised packageTyposquatting
  132. containedcritical

    Malicious code in joi-pack (npm)

    The npm package joi-pack contained malicious code in a postinstall hook that harvested npm tokens, API keys, cloud credentials, and cryptocurrency wallet data from infected systems. The malicious script exfiltrated stolen credentials to a hardcoded C2 server at 149.28.127.35:8888.

    npmCompromised package
  133. containedcritical

    Malicious code in rimraf-utils (npm)

    rimraf-utils@1.0.5 on npm contains malicious code that impersonates the legitimate rimraf package. The postinstall script harvests sensitive credentials (npm tokens, API keys, crypto wallet seeds, private keys) and exfiltrates them to a hardcoded C2 server at 149.28.127.35:8888 over plaintext HTTP.

    npmCompromised packageTyposquatting
  134. containedcritical

    Malicious code in truffle-helper (npm)

    The npm package truffle-helper version 2.0.0 contains malicious code that executes arbitrary commands during installation via npm lifecycle scripts, fetching and executing remote content without user consent.

    npmCompromised package
  135. containedcritical

    Malicious code in @antv/matrix-util (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/matrix-util, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  136. containedcritical

    Malicious code in @antv/l7-extension-g-layer (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in an automated 22-minute burst as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  137. containedcritical

    Malicious code in bui-react-10components (npm)

    The npm package bui-react-10components was found to contain malicious code that communicates with a domain associated with malicious activity. The malicious version 99.0.0 was identified by both Amazon Inspector and the OpenSSF Package Analysis project.

    npmCompromised package
  138. containedcritical

    Malicious code in @antv/my-f2-pc (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/my-f2-pc, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  139. containedcritical

    Malicious code in @antv/stat (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/stat, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure/Kubernetes credentials, SSH keys, Docker configs, database strings, Stripe/Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  140. containedcritical

    Malicious code in @antv/narrative-text-editor (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/narrative-text-editor, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  141. containedcritical

    Malicious code in web3-core-js (npm)

    The npm package web3-core-js (version 2.0.0) contained malicious code that executed arbitrary remote commands during installation. The package mimicked the legitimate web3/web3-core ecosystem but contained only a lifecycle hook that fetched and executed attacker-controlled code via curl.

    npmCompromised packageTyposquatting
  142. containedcritical

    Malicious code in @datatrain/passenger-v3 (npm)

    The npm package @datatrain/passenger-v3 version 99.99.99 was found to contain malicious code that communicates with attacker-controlled domains and executes malicious commands. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.

    npmCompromised package
  143. containedcritical

    Malicious code in @antv/x6-angular-shape (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/x6-angular-shape, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  144. containedcritical

    Malicious code in boring-avatars-vanilla (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including boring-avatars-vanilla, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  145. containedcritical

    Malicious code in @antv/semantic-release-pnpm (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/semantic-release-pnpm, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  146. containedcritical

    Malicious code in @antv/mcp-server-antv (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/mcp-server-antv, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  147. containedcritical

    Malicious code in @antv/li-aiearth-assets (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  148. containedcritical

    Malicious code in @antv/x6-vector (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/x6-vector, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  149. containedcritical

    Malicious code in @antv/hierarchy (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/hierarchy, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  150. containedcritical

    Malicious code in identitysecuretokenserv (npm)

    The npm package identitysecuretokenserv version 10.0.0 was found to contain malicious code that communicates with domains associated with malicious activity and executes commands associated with malicious behavior. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.

    npmCompromised package
  151. containedcritical

    Malicious code in @antv/g6-wx (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g6-wx, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  152. containedcritical

    Malicious code in @antv/l7-map (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-map, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  153. containedcritical

    Malicious code in @antv/xflow-core (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/xflow-core, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  154. containedcritical

    Malicious code in @antv/webgpu-graph (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/webgpu-graph, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  155. containedcritical

    Malicious code in @citi-icg-158830/elemental-chameleon (npm)

    The npm package @citi-icg-158830/elemental-chameleon version 0.0.0-defensive-callback.1 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  156. containedcritical

    Malicious code in @antv/scale (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/scale, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  157. containedcritical

    Malicious code in @antv/gi-assets-neo4j (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-neo4j, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  158. containedcritical

    Malicious code in apex-trading (npm)

    The npm package apex-trading was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. Version 1.0.4 executes commands associated with malicious behavior.

    npmCompromised package
  159. containedcritical

    Malicious code in mcp-echarts (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including mcp-echarts, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  160. containedcritical

    Malicious code in dotenvv-tool (npm)

    The npm package dotenvv-tool is a typosquatting attack impersonating the popular dotenv package. It contains a malicious postinstall script that harvests npm credentials, environment variables, git credentials, cryptocurrency wallet data, and system information, exfiltrating them to a hardcoded C2 server.

    npmTyposquattingCompromised package
  161. containedcritical

    Malicious code in hello-world-pkg-value-value-p (npm)

    The npm package hello-world-pkg-value-value-p contains malicious code in its postinstall hook that executes a reverse shell to attacker-controlled IP 52.249.218.132 on port 8080. Installation grants unauthenticated remote code execution to the attacker with the privileges of the installing user.

    npmCompromised package
  162. containedcritical

    Malicious code in @wagni_bot/eth (npm)

    A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/eth, were published on 2026-07-09 as crypto/web3 typosquats. Each package contained a postinstall hook that steals SSH keys, wallet files, .env secrets, and exfiltrates them to a hardcoded Telegram bot.

    npmTyposquattingCompromised package
  163. containedcritical

    Malicious code in @wagni_bot/hyperliquid (npm)

    A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/hyperliquid, deployed credential-stealing malware via postinstall hooks. Published 2026-07-09, the packages exfiltrated SSH keys, cryptocurrency wallets, and .env secrets to a single Telegram bot.

    npmTyposquattingCompromised package
  164. containedcritical

    Malicious code in @wagni_bot/wagni (npm)

    A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/wagni, were published on 2026-07-09 as typosquats. Each package contains a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, .env files, and system fingerprints to a hardcoded Telegram bot.

    npmCompromised packageTyposquatting
  165. containedcritical

    Malicious code in @wagni_bot/polymarket (npm)

    The npm package @wagni_bot/polymarket is a typosquatted credential stealer that is part of a coordinated campaign of 25 malicious packages published under the @wagni_bot scope on 2026-07-09. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, and .env files to a hardcoded Telegram bot.

    npmTyposquattingCompromised package
  166. containedcritical

    Malicious code in @wagni_bot/bsc (npm)

    A coordinated campaign of 25 typosquat npm packages under the @wagni_bot scope, including @wagni_bot/bsc, were published on 2026-07-09 as credential stealers. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, and .env secrets to a single Telegram bot.

    npmTyposquattingCompromised package
  167. containedcritical

    Malicious code in @wagni_bot/polygon (npm)

    The npm package @wagni_bot/polygon is a credential stealer disguised as a Polygon SDK, part of a coordinated 25-package typosquatting campaign published under @wagni_bot on 2026-07-09. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, .env files, and system fingerprints to a hardcoded Telegram bot.

    npmTyposquattingCompromised package
  168. containedcritical

    Malicious code in @wagni_bot/metamask (npm)

    The npm package @wagni_bot/metamask is a credential stealer disguised as a MetaMask SDK, part of a coordinated campaign of 25 typosquat packages published under @wagni_bot on 2026-07-09. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, and .env files to a hardcoded Telegram bot.

    npmTyposquattingCompromised package
  169. containedcritical

    Malicious code in @wagni_bot/opensea (npm)

    A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/opensea, were published on 2026-07-09 as typosquats of legitimate crypto/web3 libraries. Each package contained a postinstall hook that steals SSH keys, cryptocurrency wallets, .env files, and other secrets, exfiltrating them to a single Telegram bot.

    npmTyposquattingCompromised package
  170. containedcritical

    Malicious code in @wagni_bot/web3 (npm)

    The npm package @wagni_bot/web3 and 24 other packages under the @wagni_bot scope are typosquats that execute a postinstall hook to steal SSH keys, cryptocurrency wallets, .env files, and other secrets, exfiltrating them to a hardcoded Telegram bot. All 25 packages are part of a single coordinated campaign published on 2026-07-09.

    npmTyposquattingCompromised package
  171. activecritical

    Malicious code in whiteboard-agent (npm)

    The whiteboard-agent npm package contains malicious code in its postinstall script that silently exposes a local HTTP server to the public internet via Cloudflare tunnel in non-interactive environments (CI/CD, build agents), creates an unauthenticated admin account, and fetches an unsigned binary from a mutable release tag.

    npmCompromised packageMalicious commit
  172. containedcritical

    Malicious code in supership-scan (npm)

    The npm package supership-scan contains malicious code that exfiltrates source code and environment files (including .env files with secrets) to an attacker-controlled endpoint (https://supership.crestsystems.ai/scan/), despite marketing claims that code never leaves the machine. The package is particularly dangerous when used as an MCP server with AI coding agents.

    npmCompromised packageMalicious commit
  173. containedcritical

    Malicious code in secdriven (npm)

    The npm package 'secdriven' version 1.0.8 contains malicious postinstall code that exfiltrates host identity, username, working directory, and CI environment variables to a third-party OOB-detection endpoint. The package is a dependency-confusion payload targeting Google's internal namespace, masquerading as a security research canary.

    npmDependency confusionCompromised package
  174. containedcritical

    Malicious code in seekcode (npm)

    The seekcode npm package contains malicious code that redirects users selecting the deepseek-cn provider to a typosquatted domain (api.deepseeki.com instead of api.deepseek.com), exfiltrating API credentials and chat prompt contents to an attacker-controlled server.

    npmCompromised packageTyposquatting
  175. resolvedcritical

    Malicious code in tempo-components (npm)

    The npm package tempo-components contained malicious code (poc.js) that collected host metadata and identity information and exfiltrated it to an external endpoint. The package performed system reconnaissance by capturing hostname, platform, and user identity before transmitting the data via HTTPS.

    npmCompromised package
  176. resolvedcritical

    Malicious code in wrld-dev (npm)

    The npm package wrld-dev contained malicious code that silently relayed user authentication credentials (email and password) to an attacker-controlled Supabase tenant. The package also shipped hardcoded Supabase service_role JWT tokens that grant full database admin access to two Supabase projects.

    npmCompromised package
  177. activecritical

    Malicious code in xy-ai-chat (npm)

    The npm package xy-ai-chat contains a Lit web component that silently exfiltrates all end-user chat input to a hardcoded attacker-controlled server (182.43.87.39) over plain HTTP with no TLS or configurability. Any site embedding this component routes user data to the attacker without consent or visibility.

    npmCompromised package
  178. resolvedcritical

    Malicious code in pretty-logger-utils (npm)

    pretty-logger-utils is a malicious npm package that triggers malware behavior from a dependency (terminal-logger-utils) upon installation or import. The attack chain includes a postinstall hook that executes an obfuscated dropper, which downloads and runs a platform-specific second-stage binary from Hugging Face that provides keylogger, infostealer, and RAT capabilities.

    npmCompromised package
  179. containedcritical

    Malicious code in vfat-tools (npm)

    The npm package vfat-tools version 2.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  180. containedcritical

    Malicious code in sickle-wrapper (npm)

    The npm package sickle-wrapper version 0.2.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  181. containedcritical

    Malicious code in paysafe-gbp-virtual-terminal-lib-fe (npm)

    The npm package paysafe-gbp-virtual-terminal-lib-fe version 3.1.13 was found to contain malicious code that communicates with domains associated with malicious activity and executes commands associated with malicious behavior. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.

    npmCompromised package
  182. containedcritical

    Malicious code in @antv/g-webgpu-raytracer (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-webgpu-raytracer, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  183. containedcritical

    Malicious code in @antv/g6-element (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g6-element. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure/Kubernetes credentials, SSH keys, Docker configs, database strings, Stripe/Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  184. containedcritical

    Malicious code in @antv/gatsby-theme (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gatsby-theme. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  185. activecritical

    Malicious code in @antv/gi-assets-hugegraph (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-hugegraph. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  186. containedcritical

    Malicious code in @antv/gi-assets-tugraph (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages in a 22-minute automated burst, part of the "Mini Shai-Hulud" supply chain attack campaign. @antv/gi-assets-tugraph was among the affected packages, modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  187. containedcritical

    Malicious code in @antv/l7-mapkit (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-mapkit, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  188. containedcritical

    Malicious code in @antv/s2-react-components (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/s2-react-components, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  189. containedcritical

    Malicious code in @antv/x6-components (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/x6-components, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  190. containedcritical

    Malicious code in apex-connector (npm)

    The npm package apex-connector version 1.0.4 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.

    npmCompromised package
  191. containedcritical

    Malicious code in claude-code-base-action (npm)

    The npm package claude-code-base-action v2.0.0 was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  192. containedcritical

    Malicious code in @antv/g6-alipay (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g6-alipay, in a coordinated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  193. containedcritical

    Malicious code in @antv/g6-cli (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-cli, in an automated 22-minute burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure/Kubernetes credentials, SSH keys, Docker configs, database strings, Stripe/Slack tokens) via the GitHub API. The attack also establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  194. containedcritical

    Malicious code in @antv/g6-mobile (npm)

    The npm account `atool` was compromised, leading to publication of 631 malicious versions across 314 npm packages including @antv/g6-mobile. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  195. containedcritical

    Malicious code in @antv/g-webgl-compute (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-webgl-compute, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  196. containedcritical

    Malicious code in @antv/g6-plugin-map-view (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g6-plugin-map-view, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmCompromised packageAccount takeover
  197. containedcritical

    Malicious code in tubebrain (npm)

    The npm package tubebrain contained malicious code that exfiltrated environment variables and GitHub API interactions to an attacker-controlled domain (transscendsurvival.org). The package was identified by OpenSSF and published as a GitHub advisory.

    npmCompromised package
  198. resolvedcritical

    Malicious code in superacli (npm)

    The npm package superacli contained malicious code in plugins/gopass/daemon.js that established an unauthorized WebSocket connection to a hardcoded IP address (92.113.145.178:8768), allowing remote operators to execute arbitrary commands against the user's local gopass password store and exfiltrate decrypted secrets.

    npmCompromised packageMalicious commit
  199. resolvedcritical

    Malicious code in skipshot-agent (npm)

    The npm package skipshot-agent contained malicious code in its install script that exfiltrated environment variables to an attacker-controlled Cloudflare Workers endpoint. The package performed an unconditional POST request to https://edge-gateway.botmarket.workers.dev during installation, leaking process.env values including API keys, cloud credentials, and CI tokens.

    npmCompromised package
  200. containedcritical

    Malicious code in swift-optimizer (npm)

    swift-optimizer@1.1.0 on npm contains malicious postinstall code that fetches and executes a binary from Azure blob storage. The attack is targeted to specific organizations via hardcoded victim fingerprints derived from domain and hostname hashes.

    npmCompromised packageMalicious commit
  201. containedcritical

    Malicious code in @antv/gi-assets-algorithm (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-assets-algorithm, in an automated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  202. containedcritical

    Malicious code in your-unique-package-name1 (npm)

    Malicious code in npm package your-unique-package-name1 exfiltrates authenticated Pendo session data from end users via hidden iframe and webhook beaconing. The package was identified by OpenSSF as a live attack rather than a contained proof-of-concept.

    npmCompromised package
  203. containedcritical

    Malicious code in @antv/gi-sdk-app (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-sdk-app. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  204. containedcritical

    Malicious code in @antv/l7-editor (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-editor, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  205. containedcritical

    Malicious code in gantt-for-react (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including gantt-for-react, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  206. containedcritical

    Malicious code in @antv/g6-extension-3d (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-extension-3d, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  207. containedcritical

    Malicious code in @antv/g2-ssr (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g2-ssr, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised packageMalicious commit
  208. containedcritical

    Malicious code in @antv/g6-plugin (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g6-plugin, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  209. containedcritical

    Malicious code in @antv/gi-assets-basic (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-assets-basic, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  210. activecritical

    Malicious code in @antv/gi-assets-graphscope (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/gi-assets-graphscope. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  211. containedcritical

    Malicious code in ai-figure (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including ai-figure, in an automated attack. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  212. containedcritical

    Malicious code in @antv/gi-assets-scene (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-scene. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  213. containedcritical

    Malicious code in @antv/gi-public-data (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages in a 22-minute automated burst, part of the "Mini Shai-Hulud" supply chain attack campaign. @antv/gi-public-data was among the affected packages, modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  214. containedcritical

    Malicious code in @antv/gi-sdk (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-sdk, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure/Kubernetes credentials, SSH keys, Docker configs, database strings, Stripe/Slack tokens) via the GitHub API. The attack also establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  215. resolvedcritical

    Malicious code in @convera/ui-shared (npm)

    The npm package @convera/ui-shared version 0.0.2 contained malicious code that exfiltrated system hostname and username during installation via a preinstall script. The package was published under a private namespace scope, creating a dependency-confusion attack surface against the Convera organization.

    npmCompromised packageDependency confusion
  216. containedcritical

    Malicious code in @antv/interaction (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/interaction, in an automated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  217. containedcritical

    Malicious code in @antv/gi-mock-data (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-mock-data, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  218. activecritical

    Malicious code in @cap-js/openapi (npm)

    The npm package @cap-js/openapi was compromised and found to contain malicious code. The package steals credentials and propagates them to other packages it has access to, with persistence mechanisms. This is attributed to the "Mini Shai-Hulud is back" worm campaign by the TeamPCP threat actor.

    Mini Shai HuludTeamPCPnpmCompromised packageMalicious maintainer
  219. containedcritical

    Malicious code in @apps-home-dashboard/events (npm)

    The npm package @apps-home-dashboard/events version 11.9.1 was found to contain malicious code that communicates with domains associated with malicious activity and executes suspicious commands. The package was identified as malicious by both Amazon Inspector and the OpenSSF Package Analysis project.

    npmCompromised package
  220. activecritical

    Malicious code in @antv/l7-scene (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-scene, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  221. containedcritical

    Malicious code in @antv/li-editor (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/li-editor, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  222. activecritical

    Malware in log-taker1

    The npm package log-taker1 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  223. containedcritical

    Malicious code in mcp-mermaid (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including mcp-mermaid, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  224. containedcritical

    Malicious code in jest-canvas-mock (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including jest-canvas-mock, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  225. resolvedcritical

    Malicious code in @pelmnaads/naads-common-logger (npm)

    Malicious code in @pelmnaads/naads-common-logger (npm) version 19999.0.1 exploited dependency confusion by publishing to the public npm registry with an abnormally high version number. A preinstall script transmitted installer hostname data to a Burp Collaborator endpoint (h5nvwrz2815ubw84cpkwhezm5db9z1nq.b.mburpcollab.com), silently exfiltrating build host identity.

    npmDependency confusionCompromised package
  226. containedcritical

    Malicious code in hardhat-core (npm)

    The npm package hardhat-core v1.0.0 is a typosquat of the legitimate hardhat package that executes a malicious postinstall script. The script base64-decodes a URL, fetches a payload over plain HTTP from a hardcoded IP address, and pipes it directly into bash, executing arbitrary attacker-controlled code during installation.

    npmTyposquattingCompromised package
  227. activecritical

    Malware in demo-awesome-date-parser-test

    The npm package demo-awesome-date-parser-test contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  228. containedcritical

    Malware in f0-fpti-tracking-manager

    Malware was discovered in the npm package f0-fpti-tracking-manager. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  229. containedcritical

    Malware in rainbokit

    Malware was discovered in the npm package rainbokit, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  230. containedcritical

    Malware in identityauthorizationserv

    The npm package identityauthorizationserv was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  231. containedcritical

    Malware in nemo-jaws

    Malware was discovered in the npm package nemo-jaws, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.

    npmCompromised package
  232. containedcritical

    Malware in fundraiserserv

    Malware was discovered in the npm package fundraiserserv. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  233. containedcritical

    Malware in xo-twofa

    The npm package xo-twofa contained malware that fully compromised any system where it was installed. GitHub Security Advisory GHSA-7v73-c7c7-mr5x documents the incident as critical severity.

    npmCompromised package
  234. activecritical

    Malware in xo-member-components

    The npm package xo-member-components was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  235. activecritical

    Malware in filifecycleserv-paypal

    Malware discovered in the npm package filifecycleserv-paypal. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  236. containedcritical

    Malware in gpaas-paypal

    The npm package gpaas-paypal was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  237. containedcritical

    Malware in merchantprefsservice-paypal

    Malware was discovered in the npm package merchantprefsservice-paypal. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  238. containedcritical

    Malware in identityscimapiserv

    Malware was discovered in the npm package identityscimapiserv. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  239. activecritical

    Malware in preferenceslifecycle-paypal

    The npm package preferenceslifecycle-paypal contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  240. activecritical

    Malware in payoutsvettingserv-paypal

    Malware discovered in the npm package payoutsvettingserv-paypal. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  241. containedcritical

    Malware in @immobiliarelabs/backstage-plugin-gitlab

    Malware was discovered in the npm package @immobiliarelabs/backstage-plugin-gitlab. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  242. containedcritical

    Malware in f0-data-constructor

    Malware was discovered in the npm package f0-data-constructor. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  243. containedcritical

    Malware in f0-form-manipulator

    The npm package f0-form-manipulator was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  244. containedcritical

    Malware in @vinnxcode/xbailsync

    The npm package @vinnxcode/xbailsync contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  245. activecritical

    Malware in riskunifiedgatewayserv

    Malware was discovered in the npm package riskunifiedgatewayserv. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.

    npmCompromised package
  246. containedcritical

    Malware in stargateproxyserv

    The npm package stargateproxyserv was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  247. activecritical

    Malware in crm-reportinsightserv-paypal

    Malware discovered in the npm package crm-reportinsightserv-paypal. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  248. containedcritical

    Malware in pp-react-ui5

    Malware was discovered in the npm package pp-react-ui5. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  249. activecritical

    Malware in tailwind-motionkit

    The npm package tailwind-motionkit contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  250. activecritical

    Malware in route-processor

    Malware discovered in the npm package route-processor. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  251. activecritical

    Malware in @array-util/subsearch

    Malware discovered in the npm package @array-util/subsearch. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  252. activecritical

    Malware in @array-util/nodepull

    Malware discovered in the npm package @array-util/nodepull. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  253. containedcritical

    Malware in animated-css-kit

    The npm package animated-css-kit contained malware that could fully compromise affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  254. containedcritical

    Malware in gamified-trading-system

    The npm package gamified-trading-system contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  255. activecritical

    Malware in font-huge

    Malware discovered in the npm package font-huge. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  256. containedcritical

    Malware in npx-whoami-demo

    The npm package npx-whoami-demo was found to contain malware. Any system with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  257. activecritical

    Malware in kalipto-runtime

    Malware discovered in the npm package kalipto-runtime. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  258. activecritical

    Malware in fluterjs

    Malware discovered in the npm package fluterjs. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  259. activecritical

    Malware in @kalipto/local

    The npm package @kalipto/local contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  260. resolvedcritical

    Malware in gifuct

    The npm package gifuct was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  261. activecritical

    Malware in svg-fetcher

    Malware discovered in the npm package svg-fetcher. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  262. resolvedcritical

    Malware in @my_name_is_khn/express-security-tool

    The npm package @my_name_is_khn/express-security-tool contained malware that could fully compromise any system where it was installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  263. containedcritical

    Malware in @my_name_is_khn/express-security-tool-v2

    The npm package @my_name_is_khn/express-security-tool-v2 contained malware that could fully compromise any system where it was installed or executed. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  264. activecritical

    Malware in express-timer

    Malware discovered in the npm package express-timer. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  265. containedcritical

    Malware in @my_name_is_khn/express-security-tool-v3

    The npm package @my_name_is_khn/express-security-tool-v3 contained malware that could fully compromise any system where it was installed or executed. The package has been identified and removed from distribution.

    npmCompromised package
  266. resolvedcritical

    Malware in @my_name_is_khn/express-security-tool-v1

    The npm package @my_name_is_khn/express-security-tool-v1 contained malware that could fully compromise any system where it was installed or executed. GitHub Security Advisory GHSA-v624-m435-vmfx documents the incident.

    npmCompromised package
  267. containedcritical

    Malware in express-self-destruct

    The npm package express-self-destruct contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  268. containedcritical

    Malicious code in cheerio-tool (npm)

    cheerio-tool, a typosquatting package on npm impersonating the popular cheerio HTML parser, contained malicious postinstall code that harvested npm credentials, API keys, cloud credentials, and cryptocurrency wallet data from infected systems.

    npmTyposquattingCompromised package
  269. activecritical

    Malware in express-self-destruct2

    Malware discovered in the npm package express-self-destruct2. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.

    npmCompromised package
  270. activecritical

    Malware in express-self-destruct1

    Malware discovered in the npm package express-self-destruct1. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.

    npmCompromised package
  271. containedcritical

    Malware in @ceeferenderer/itg-renderer-sdk

    Malware was discovered in the npm package @ceeferenderer/itg-renderer-sdk. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  272. containedcritical

    Malware in hardhat-compile-ethers

    Malware was discovered in the npm package hardhat-compile-ethers, providing full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  273. containedcritical

    Malware in @equansservices/tool

    Malware was discovered in the npm package @equansservices/tool. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  274. containedcritical

    Malware in supertokens-web

    Malware was discovered in the supertokens-web npm package. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  275. containedcritical

    Malware in tinymask-js

    Malware was discovered in the npm package tinymask-js. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  276. activecritical

    Malware in llama-tokenizer

    The npm package llama-tokenizer contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  277. activecritical

    Malware in @sqlite-frame/nodesql

    Malware discovered in the npm package @sqlite-frame/nodesql. Systems with this package installed are considered fully compromised and may have given outside entities complete control.

    npmCompromised package
  278. activecritical

    Malware in @sqlite-tag/schema-generator

    Malware was discovered in the npm package @sqlite-tag/schema-generator. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  279. activecritical

    Malware in @sqlite-tag/sql-creator

    The npm package @sqlite-tag/sql-creator was found to contain malware. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  280. containedcritical

    Malware in fazzanime

    The npm package fazzanime was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  281. resolvedcritical

    Malware in fazzgram

    The npm package fazzgram contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  282. activecritical

    Malware in amanexzyra-baileys

    The npm package amanexzyra-baileys contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  283. containedcritical

    Malware in @fazzcode/baileys

    Malware was discovered in the npm package @fazzcode/baileys. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  284. containedcritical

    Malware in @ceeferenderer/fe-renderer-sdk

    Malware was discovered in the npm package @ceeferenderer/fe-renderer-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  285. activecritical

    Malware in @wrenfield/abitype

    Malware discovered in the npm package @wrenfield/abitype. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  286. activecritical

    Malware in @wrenfield/viem

    The npm package @wrenfield/viem contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  287. resolvedcritical

    Malware in @vinnxcode/libsignal-node

    The npm package @vinnxcode/libsignal-node contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different system.

    npmCompromised package
  288. resolvedcritical

    Malware in sixbails

    The npm package sixbails was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  289. containedcritical

    Malware in permcarmserver

    The npm package permcarmserver was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  290. resolvedcritical

    Malware in permcserver

    The npm package permcserver contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  291. activecritical

    Malware in log-taker

    The npm package log-taker contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  292. containedcritical

    Malware in ts-escro

    The npm package ts-escro was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  293. resolvedcritical

    Malware in thirdwb

    The npm package thirdwb contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  294. containedcritical

    Malware in rainbownkit

    Malware was discovered in the npm package rainbownkit, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  295. containedcritical

    Malware in thirdwebjs

    The npm package thirdwebjs was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  296. containedcritical

    Malware in thurdweb

    The npm package thurdweb was compromised and distributed with malware, resulting in full system compromise for any installation. All secrets and keys on affected systems should be rotated immediately from a clean machine.

    npmCompromised package
  297. resolvedcritical

    Malicious code in yessir-node (npm)

    yessir-node, a malicious npm package, executes code on require() that modifies @whiskeysockets/baileys to force-subscribe authenticated WhatsApp accounts to attacker-controlled channels. The package masquerades as a libsignal implementation while performing destructive dependency tampering.

    npmCompromised package
  298. resolvedcritical

    Malware in thirdwebb

    The npm package thirdwebb contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  299. containedcritical

    Malware in therdweb

    Malware was discovered in the npm package therdweb, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a different computer.

    npmCompromised package
  300. containedcritical

    Malware in thidweb

    The npm package thidweb was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  301. containedcritical

    Malware in ts-escrow

    Malware was discovered in the ts-escrow npm package. Systems with the package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.

    npmCompromised package
  302. containedcritical

    Malware in polymarket-stake-maths

    The npm package polymarket-stake-maths contained malware that could fully compromise any system where it was installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  303. activecritical

    Malware in chai-log

    Malware discovered in the npm package chai-log. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  304. activecritical

    Malware in @sqlite-frame/createsql

    Malware was discovered in the npm package @sqlite-frame/createsql. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  305. containedcritical

    Malicious code in prisma-callback (npm)

    prisma-callback@1.0.3 is a typosquatting package impersonating the legitimate Prisma ORM. It contains a preinstall script that executes undeclared, opaque native Go binaries (prisma-amd64 or prisma-arm64) at install time without integrity verification.

    npmTyposquattingCompromised package
  306. resolvedcritical

    Malicious code in prettier-lint-lenz (npm)

    The npm package prettier-lint-lenz is a malicious imposter of the legitimate Prettier formatter. It executes a postinstall script that deploys clipboard-stealing malware on Windows systems, establishing persistence via a scheduled task that exfiltrates clipboard contents to a hardcoded C2 server.

    npmCompromised packageTyposquatting
  307. containedcritical

    Malware in txs-sdk-lib

    Malware was discovered in the npm package txs-sdk-lib, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  308. activecritical

    Malware in txs-random-lib

    Malware discovered in the npm package txs-random-lib. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  309. containedcritical

    Malware in txs-runner-lib

    Malware was discovered in the npm package txs-runner-lib, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  310. containedcritical

    Malware in txs-builder

    The npm package txs-builder was found to contain malware, potentially giving outside entities full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  311. activecritical

    Malware in v018-axios-cdntest

    The npm package v018-axios-cdntest contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  312. containedcritical

    Malware in edu-npm-helper-alpha

    Malware was discovered in the npm package edu-npm-helper-alpha. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  313. containedcritical

    Malware in edu-npm-helper-beta

    Malware was discovered in the npm package edu-npm-helper-beta. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  314. resolvedcritical

    Malware in edu-npm-postinstall-demo2

    Malware was discovered in the npm package edu-npm-postinstall-demo2. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  315. activecritical

    Malware in edu-npm-dependency-chain-demo

    Malware discovered in the npm package edu-npm-dependency-chain-demo. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  316. containedcritical

    Malware in roblox-api-client

    Malware was discovered in the npm package roblox-api-client, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  317. activecritical

    Malware in @thone33/analytics-injector

    Malware discovered in the npm package @thone33/analytics-injector. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  318. containedcritical

    Malware in @thone33/react-helpers

    Malware was discovered in the npm package @thone33/react-helpers, granting full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  319. containedcritical

    Malware in @thone33/core-utils

    Malware was discovered in the npm package @thone33/core-utils, granting full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  320. activecritical

    Malware in @403name/fsevent

    Malware discovered in the npm package @403name/fsevent. Systems with this package installed are considered fully compromised with potential for complete system control by an external entity.

    npmCompromised package
  321. activecritical

    Malware in @403name/ether-js

    Malware was distributed via the npm package @403name/ether-js. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  322. resolvedcritical

    Malware in @403name/electron-buidler

    The npm package @403name/electron-buidler contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different machine.

    npmCompromised package
  323. activecritical

    Malware in ap3-components-ui

    Malware discovered in the npm package ap3-components-ui. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  324. containedcritical

    Malicious code in node-ci-utils (npm)

    The npm package node-ci-utils contained malicious code that, on require(), downloads and executes an unsigned binary from attacker-controlled infrastructure. The package used obfuscation techniques (base64-encoded URL, single-letter variables) to evade detection.

    npmCompromised package
  325. containedcritical

    Malware in jextic-eclib

    Malware was discovered in the npm package jextic-eclib, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  326. containedcritical

    Malicious code in exxpress-utils (npm)

    The npm package exxpress-utils contained malicious code in a postinstall script that harvested npm/AWS/GitHub credentials, scanned for cryptocurrency wallet extensions, and exfiltrated sensitive files to a hardcoded C2 server. The package was a typosquat of the legitimate 'express' package.

    npmCompromised packageTyposquatting
  327. containedcritical

    Malicious code in sysbin (npm)

    The npm package sysbin contains malicious code that executes a Python stealth overlay (pointer.py) on installation or require(), exfiltrating clipboard contents and screenshots to a hardcoded attacker endpoint. The package includes a 'ghost installer' that silently installs Python if absent, bypassing user prompts.

    npmCompromised package
  328. resolvedcritical

    Malware in @ci-lifecycle-test/postinstall-ping

    Malware was distributed via the npm package @ci-lifecycle-test/postinstall-ping. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  329. containedcritical

    Malicious code in typography-stylecss (npm)

    The npm package typography-stylecss is a typosquatting attack impersonating the legitimate @tailwindcss/typography plugin. It contains obfuscated malicious code that downloads and executes a platform-specific binary when the module is imported, triggered automatically during Tailwind config loading.

    npmTyposquattingCompromised package
  330. containedcritical

    Malicious code in solc-helper (npm)

    The npm package solc-helper version 2.0.0 contains malicious code in its postinstall lifecycle script that downloads and executes arbitrary shell code from an attacker-controlled server. Every installation triggers an unattended download-and-execute of remote code via curl piped to bash from a bare IP address over plaintext HTTP.

    npmCompromised package
  331. containedcritical

    Malicious code in pinno-loggers (npm)

    pinno-loggers is a malicious npm package that depends on terminal-logger-utils and executes a multi-stage malware payload via postinstall hooks. The second-stage binary provides keylogger, infostealer, and RAT capabilities, stealing sensitive data including credentials, SSH keys, and crypto wallets.

    npmCompromised packageMalicious commit
  332. containedcritical

    Malicious code in polymarket-auto-trade (npm)

    A coordinated supply-chain attack published 9 malicious npm packages under the polymarketdev maintainer on 2026-05-20, masquerading as Polymarket CLOB trading tools. The packages exfiltrate Ethereum private keys via postinstall hooks to a Cloudflare Worker C2 endpoint, with adaptive evasion for CI/CD scanners.

    npmCompromised packageMalicious maintainer
  333. containedcritical

    Malicious code in polymarket-trader (npm)

    A coordinated supply-chain attack published 9 malicious npm packages by maintainer polymarketdev on 2026-05-20, masquerading as Polymarket CLOB trading tools. The packages exfiltrate Ethereum private keys via postinstall hooks to a Cloudflare Worker C2 endpoint, with evasion techniques targeting CI/CD scanners.

    npmMalicious maintainerCompromised package
  334. containedcritical

    Malicious code in polymarket-terminal (npm)

    A coordinated supply-chain attack published 9 malicious npm packages by maintainer polymarketdev on 2026-05-20, masquerading as Polymarket CLOB trading tools. The packages exfiltrate Ethereum private keys via postinstall hooks to a Cloudflare Worker C2 endpoint, with adaptive evasion for CI/CD scanners and silent extraction from .env files.

    npmMalicious maintainerCompromised package
  335. resolvedcritical

    Malicious code in @akunsansan0/pucuk9 (npm)

    The npm package @akunsansan0/pucuk9 contained malicious code designed to automatically generate and publish derivative packages with randomized names to the npm registry. The package was part of a broader campaign to inflate developer reputation scores for tea protocol token rewards.

    npmCompromised package
  336. containedcritical

    Malicious code in @antv/g-css-layout-api (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-css-layout-api, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  337. containedcritical

    Malicious code in @antv/dw-util (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/dw-util, each injecting a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via GitHub API. The attack also establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  338. resolvedcritical

    Malicious code in @akunsansan0/teagunz99 (npm)

    @akunsansan0/teagunz99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmCompromised package
  339. containedcritical

    Malicious code in @angular_devkit/core (npm)

    Version 99.1.1 of @angular_devkit/core (npm) was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.

    npmCompromised package
  340. containedcritical

    Malicious code in @antstackio/shelbysam (npm)

    The npm package @antstackio/shelbysam was compromised and contained malicious code associated with the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates to other NPM packages owned by the user, and may destroy the user's home directory.

    Shai-HuludnpmCompromised packageMalicious commit
  341. containedcritical

    Malicious code in @antv/g-plugin-webgpu-device (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-webgpu-device, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  342. containedcritical

    Malicious code in @antv/g-dom-mutation-observer-api (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-dom-mutation-observer-api, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  343. containedcritical

    Malicious code in @antv/data-samples (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/data-samples. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  344. containedcritical

    Malicious code in @antv/g-plugin-mobile-interaction (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-mobile-interaction, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  345. containedcritical

    Malicious code in @antv/dw-transform (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/dw-transform. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  346. containedcritical

    Malicious code in @antv/f6-hammerjs (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f6-hammerjs, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  347. containedcritical

    Malicious code in @antv/f2-algorithm (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f2-algorithm, in a coordinated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  348. containedcritical

    Malicious code in @antv/g-plugin-webgl-device (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-webgl-device, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  349. containedcritical

    Malicious code in @antv/f2-my (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f2-my, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  350. containedcritical

    Malicious code in @antv/g-plugin-yoga (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-plugin-yoga, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  351. containedcritical

    Malicious code in @antv/g-plugin-css-select (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-css-select, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  352. containedcritical

    Malicious code in @antv/chart-visualization-skills (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/chart-visualization-skills, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  353. containedcritical

    Malicious code in @antv/g-plugin-annotation (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-annotation. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    npmOtherAccount takeoverCompromised packageMalicious commit
  354. containedcritical

    Malicious code in @antv/g-web-components (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/g-web-components. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  355. containedcritical

    Malicious code in @antv/g-plugin-svg-picker (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-svg-picker, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  356. resolvedcritical

    Malicious code in @akunsansan0/pucuk11 (npm)

    @akunsansan0/pucuk11 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and pollutes the npm registry with variants.

    npmCompromised packageMalicious commit
  357. containedcritical

    Malicious code in @antv/g-camera-api (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-camera-api. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  358. resolvedcritical

    Malicious code in @alaska-its/design-tokens (npm)

    Malicious code was discovered in the npm package @alaska-its/design-tokens. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-56q2-v4w4-rwhm.

    npmCompromised package
  359. containedcritical

    Malicious code in @antv/g-css-typed-om-api (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages in an automated attack. @antv/g-css-typed-om-api was among the affected packages, modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  360. containedcritical

    Malicious code in @antv/data-set (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/data-set. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  361. containedcritical

    Malicious code in @antv/f2-wordcloud (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f2-wordcloud, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  362. containedcritical

    Malicious code in @antv/chart-linter (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/chart-linter, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure credentials, SSH keys, Docker configs, database strings, API keys) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  363. containedcritical

    Malicious code in @antstackio/express-graphql-proxy (npm)

    The npm package @antstackio/express-graphql-proxy was compromised and contained malicious code as part of the Sha1-Hulud: The Second Coming NPM worm. The malware steals tokens and credentials, publishes them to GitHub, propagates to other packages owned by the user, and may destroy the user's home directory.

    Shai-HuludnpmCompromised packageMalicious commit
  364. containedcritical

    Malicious code in @antv/f2-site (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/f2-site, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmCompromised packageAccount takeover
  365. containedcritical

    Malicious code in @antstackio/json-to-graphql (npm)

    The npm package @antstackio/json-to-graphql was compromised and contained malicious code as part of the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates to other npm packages owned by the user, and may destroy the user's home directory.

    Shai-HuludnpmCompromised packageMalicious commit
  366. containedcritical

    Malicious code in @antv/dipper-component (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/dipper-component, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  367. containedcritical

    Malicious code in @antv/g-pattern (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-pattern, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  368. resolvedcritical

    Malicious code in @amber-team/react-modal-stack (npm)

    The npm package @amber-team/react-modal-stack was found to contain malicious code. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Security Advisory GHSA-44rm-8vq6-qhf5.

    npmCompromised package
  369. containedcritical

    Malicious code in @andes-tools/colors (npm)

    The npm package @andes-tools/colors version 999.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  370. resolvedcritical

    Malicious code in @amiga-fwk-nodejs/log (npm)

    The npm package @amiga-fwk-nodejs/log was found to contain malicious code. The package has been identified and documented by the OpenSSF malicious packages project.

    npmCompromised package
  371. containedcritical

    Malicious code in @antv/g-device-api (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-device-api. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  372. containedcritical

    Malicious code in @antv/g-plugin-dom-interaction (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-dom-interaction, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  373. resolvedcritical

    Malicious code in @anchor-ds/core (npm)

    The npm package @anchor-ds/core was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.

    npmCompromised package
  374. resolvedcritical

    Malicious code in @amber-team/gatsby-plugin-semcore (npm)

    The npm package @amber-team/gatsby-plugin-semcore was found to contain malicious code. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-27jr-546m-cv6p.

    npmCompromised package
  375. resolvedcritical

    Malicious code in @al-ui/useappinsights (npm)

    Malicious code was discovered in the npm package @al-ui/useappinsights. The package was identified by the OpenSSF malicious-packages project as containing malicious code.

    npmCompromised package
  376. resolvedcritical

    Malicious code in @akunsansan0/susu2 (npm)

    @akunsansan0/susu2 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to the npm registry. The package was part of a tea.xyz token reward campaign that flooded npm with similar malicious packages.

    npmCompromised package
  377. containedcritical

    Malicious code in @antv/dipper-hooks (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/dipper-hooks, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  378. resolvedcritical

    Malicious code in @angular_devkit/build_angular (npm)

    Malicious code was discovered in the npm package @angular_devkit/build_angular. The compromised package contained code that communicates with a domain associated with malicious activity. The incident was identified and reported by the OpenSSF malicious packages project.

    npmCompromised package
  379. containedcritical

    Malicious code in @angular_devkit/architect (npm)

    Malicious code was discovered in the npm package @angular_devkit/architect. The package contained code that communicates with a domain associated with malicious activity. The incident was identified and reported by the OpenSSF malicious packages project.

    npmCompromised package
  380. resolvedcritical

    Malicious code in @alphasedboy/game (npm)

    Malicious code was discovered in the npm package @alphasedboy/game. The package was flagged by the OpenSSF malicious-packages project and assigned advisory GHSA-9587-gmc9-6qh8.

    npmCompromised package
  381. resolvedcritical

    Malicious code in @aluffyz/discord-botjs (npm)

    The npm package @aluffyz/discord-botjs version 1.4.5 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  382. containedcritical

    Malicious code in @akunsansan0/tehpucuk1 (npm)

    @akunsansan0/tehpucuk1 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmMalicious commitCompromised package
  383. resolvedcritical

    Malicious code in @akunsansan0/tea_guntry99 (npm)

    @akunsansan0/tea_guntry99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmCompromised packageMalicious commit
  384. resolvedcritical

    Malicious code in @amiga-fwk-nodejs/metrics (npm)

    The npm package @amiga-fwk-nodejs/metrics was found to contain malicious code. The package has been identified and reported by the OpenSSF malicious packages project.

    npmCompromised package
  385. resolvedcritical

    Malicious code in @akunsansan0/teagunup99 (npm)

    @akunsansan0/teagunup99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.

    npmCompromised packageMalicious commit
  386. resolvedcritical

    Malicious code in @akunsansan0/karedok36 (npm)

    @akunsansan0/karedok36 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmCompromised packageMalicious commit
  387. containedcritical

    Malicious code in @antv/data-wizard (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/data-wizard. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  388. containedcritical

    Malicious code in @antv/g-plugin-physx (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-plugin-physx, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  389. resolvedcritical

    Malicious code in @akunsansan0/tea_gunt99 (npm)

    @akunsansan0/tea_gunt99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.

    npmCompromised packageMalicious commit
  390. resolvedcritical

    Malicious code in @alexandrsarioglo/npm-ghost-htb (npm)

    The npm package @alexandrsarioglo/npm-ghost-htb was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.

    npmCompromised package
  391. resolvedcritical

    Malicious code in @akunsansan0/susu8 (npm)

    @akunsansan0/susu8 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modifies package.json, removes private flags, and pollutes the npm registry with variants.

    npmCompromised package
  392. resolvedcritical

    Malicious code in @antstackio/eslint-config-antstack (npm)

    The npm package @antstackio/eslint-config-antstack was compromised and contained malicious code as part of the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates itself to other NPM packages owned by the user, and may destroy the user's home directory.

    Shai-HuludnpmCompromised packageMalicious commit
  393. resolvedcritical

    Malicious code in @aligntech-cw/alignerfit (npm)

    Malicious code was discovered in the npm package @aligntech-cw/alignerfit. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-1743.

    npmCompromised package
  394. resolvedcritical

    Malicious code in @akunsansan0/susu10 (npm)

    @akunsansan0/susu10 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to the npm registry. The package was part of a tea.xyz token reward campaign that flooded npm with similar malicious packages.

    npmCompromised package
  395. containedcritical

    Malicious code in @antv/f2-canvas (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/f2-canvas, each injecting a preinstall hook that executes an obfuscated Bun script to exfiltrate credentials and establish persistence. The attack was part of the "Mini Shai-Hulud" supply chain attack campaign.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  396. resolvedcritical

    Malicious code in @akunsansan0/susu11 (npm)

    @akunsansan0/susu11 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, changes version numbers, and continuously pollutes the npm registry with variants.

    npmCompromised package
  397. resolvedcritical

    Malicious code in @akunsansan0/susu3 (npm)

    @akunsansan0/susu3 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmCompromised package
  398. containedcritical

    Malicious code in @andrewstory18/is-real-odd (npm)

    @andrewstory18/is-real-odd is a malicious npm package that impersonates the legitimate is-odd package by copying its metadata, but includes an obfuscated postinstall script that exfiltrates data to a hardcoded attacker IP (144.172.91.84:3000) on installation.

    npmCompromised packageTyposquatting
  399. resolvedcritical

    Malicious code in @anhackle/test (npm)

    The npm package @anhackle/test was found to contain malicious code. The package has been identified and cataloged by the OpenSSF malicious packages project.

    npmCompromised package
  400. containedcritical

    Malicious code in @antv/f-wx (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f-wx. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  401. resolvedcritical

    Malicious code in @akunsansan0/kopi3 (npm)

    @akunsansan0/kopi3 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmCompromised package
  402. containedcritical

    Malicious code in @antv/g-plugin-webgl-renderer (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-webgl-renderer, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  403. resolvedcritical

    Malicious code in @amber-team/figma-utils (npm)

    The npm package @amber-team/figma-utils was found to contain malicious code. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Advisory GHSA-2j44-84pc-388j.

    npmCompromised package
  404. resolvedcritical

    Malicious code in @amigatechdocs/core (npm)

    The npm package @amigatechdocs/core was found to contain malicious code. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2025-42187.

    npmCompromised package
  405. containedcritical

    Malicious code in @antv/g-web-animations-api (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-web-animations-api. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  406. containedcritical

    Malicious code in @antv/g-plugin-matterjs (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-matterjs, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  407. containedcritical

    Malicious code in @amops/fetch (npm)

    The npm package @amops/fetch version 1.4.1 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    npmCompromised package
  408. resolvedcritical

    Malicious code in @amber-team/export-events-to-sheet (npm)

    The npm package @amber-team/export-events-to-sheet was found to contain malicious code. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-qxj3-92mx-9r8w.

    npmCompromised package
  409. containedcritical

    Malicious code in @antv/g-plugin-zdog-canvas-renderer (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-zdog-canvas-renderer, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  410. containedcritical

    Malicious code in @angular_devkit/build-webpack (npm)

    The npm package @angular_devkit/build-webpack version 99.1.1 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.

    npmCompromised package
  411. containedcritical

    Malicious code in @antv/g-layout-blocklike (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages in an automated attack known as "Mini Shai-Hulud." The @antv/g-layout-blocklike package was among those modified to inject a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  412. containedcritical

    Malicious code in @antv/g-perf (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-perf. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  413. containedcritical

    Malicious code in @antv/g-plugin-zdog-svg-renderer (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-zdog-svg-renderer, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP/Azure credentials, SSH keys, Docker configs, database strings, API keys) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  414. containedcritical

    Malicious code in @antv/f6-alipay (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f6-alipay, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  415. containedcritical

    Malicious code in @antv/d3-interpolate (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/d3-interpolate, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  416. containedcritical

    Malicious code in @antv/g-plugin-box2d (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g-plugin-box2d, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  417. containedcritical

    Malicious code in @antv/awards (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/awards, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  418. resolvedcritical

    Malicious code in @akunsansan0/pucuk12 (npm)

    @akunsansan0/pucuk12 on npm contained malicious code designed to automatically generate and publish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modified package.json, changed version numbers, and continuously republished variants to pollute the npm registry.

    npmCompromised package
  419. containedcritical

    Malicious code in @antv/f-charts (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f-charts, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludTeamPCPnpmAccount takeoverCompromised package
  420. containedcritical

    Malicious code in @antv/f2-wx (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/f2-wx, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  421. containedcritical

    Malicious code in @antv/calendar-heatmap (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/calendar-heatmap, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  422. containedcritical

    Malicious code in @antv/g-compat (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-compat. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  423. containedcritical

    Malicious code in @antv/f-my (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/f-my. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  424. containedcritical

    Malicious code in @antv/g-plugin-canvas-picker (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-canvas-picker. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  425. containedcritical

    Malicious code in @antv/g-plugin-canvaskit-renderer (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/g-plugin-canvaskit-renderer, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflows and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  426. containedcritical

    Malicious code in @antv/dipper-map (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/dipper-map, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmAccount takeoverCompromised package
  427. containedcritical

    Malicious code in @antv/f6-wx (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f6-wx. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    TeamPCPMini Shai HuludnpmAccount takeoverCompromised package
  428. resolvedhigh

    Malicious code in @akunsansan0/tehpucuk2 (npm)

    @akunsansan0/tehpucuk2 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards and pollute the npm registry.

    npmCompromised packageMalicious commit
  429. resolvedcritical

    Malicious code in @akunsansan0/karedok4 (npm)

    @akunsansan0/karedok4 on npm contained malicious code designed to automatically generate and publish derivative packages with randomized names to inflate developer reputation scores for tea protocol token rewards. The package modified package.json, changed version numbers, and continuously republished variants to pollute the npm registry.

    npmCompromised package
  430. resolvedcritical

    Malicious code in @akunsansan0/teaguntur99 (npm)

    @akunsansan0/teaguntur99 is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to inflate tea protocol token rewards. The package modifies package.json, removes private flags, and continuously pollutes the npm registry with variants.

    npmCompromised packageMalicious commit
  431. resolvedcritical

    Malicious code in @akunsansan0/pucukharum (npm)

    @akunsansan0/pucukharum is a malicious npm package containing autopublish scripts designed to automatically generate and republish derivative packages with randomized names to the npm registry. The package was part of a tea.xyz token reward campaign that flooded npm with similar malicious packages.

    npmCompromised packageMalicious commit
  432. resolvedcritical

    Malicious code in -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main (npm)

    Malicious code was published in the npm package "-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main". The package was identified and cataloged by the OpenSSF malicious packages database.

    npmCompromised package
  433. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-espanol (npm)

    A malicious npm package named "-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-espanol" was published containing malicious code. The package was identified and documented by the OpenSSF malicious packages project.

    npmCompromised package
  434. resolvedcritical

    Malicious code in -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love (npm)

    A malicious npm package with a deceptive name containing movie-related keywords was published to the npm registry. The package contained malicious code and was identified by the OpenSSF malicious packages project.

    npmCompromised package
  435. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-love (npm)

    A malicious npm package named "-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-love" was published containing malicious code. The package was identified and documented by the OpenSSF malicious packages project.

    npmCompromised package
  436. resolvedcritical

    Malicious code in -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-suparhit (npm)

    A malicious npm package with a typosquatting name was published containing malicious code. The package was identified and cataloged by the OpenSSF malicious packages project.

    npmCompromised package
  437. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-espanol (npm)

    Malicious code was published in an npm package with a deceptive name referencing a John Wick movie. The package was identified and cataloged by the OpenSSF malicious packages database.

    npmCompromised package
  438. containedcritical

    Malicious code in -pem-misa (npm)

    The npm package -pem-misa contains malicious code designed to automatically generate and republish derivative packages with randomized names to the npm registry. The attack is part of a broader tea.xyz token reward campaign that flooded npm with similar malicious packages.

    npmCompromised packageMalicious commit
  439. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-tarabi-lliena- (npm)

    Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and cataloged by the OpenSSF malicious packages database.

    npmCompromised package
  440. resolvedcritical

    Malicious code in -accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena- (npm)

    A malicious npm package with an obfuscated name containing Spanish-language movie references was published to npm. The package contained malicious code and was identified by the OpenSSF malicious packages project.

    npmCompromised package
  441. resolvedcritical

    Malicious code in -espanol-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love (npm)

    A malicious npm package named "-espanol-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love" was published containing malicious code. The package was identified and documented by the OpenSSF malicious packages project.

    npmCompromised package
  442. resolvedcritical

    Malicious code in -whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home (npm)

    Malicious code was published in the npm package "-whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home". The package was identified and cataloged by the OpenSSF malicious packages project.

    npmCompromised package
  443. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena- (npm)

    Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and documented by the OpenSSF malicious packages project.

    npmCompromised package
  444. resolvedcritical

    Malicious code in -john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena- (npm)

    Malicious code was published in an npm package with a deceptive name referencing a movie title. The package was identified and cataloged by the OpenSSF malicious packages database.

    npmCompromised package
  445. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-pelicula-completa-h-d-varindo-en-casa-en-lienia-lliena-love (npm)

    A malicious npm package with a deceptive movie-themed name was published to the npm registry. The package contained malicious code and was identified by the OpenSSF malicious packages project.

    npmCompromised package
  446. resolvedcritical

    Malicious code in -espanol-john-wick-keanu-reeves-4-k-varindo-en-casa-en-lienia-lliena-love (npm)

    A malicious npm package with a typosquatting name containing Spanish text and movie references was published to npm. The package contained malicious code and was identified by the OpenSSF malicious packages project.

    npmCompromised package
  447. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-en-lienia-lliena-love (npm)

    A malicious npm package with a deceptive movie-themed name was published containing malicious code. The package was identified and documented by the OpenSSF malicious packages database.

    npmCompromised package
  448. resolvedcritical

    Malicious code in -john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love (npm)

    Malicious code was published in the npm package "-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love". The package was identified by the OpenSSF malicious-packages project and reported via GitHub Advisory GHSA-7x55-g6gw-jq49.

    npmCompromised package
  449. resolvedcritical

    Malicious code in -whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-123 (npm)

    Malicious code was published in the npm package "-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-123". The package was identified and cataloged by the OpenSSF malicious packages project.

    npmCompromised package
  450. resolvedcritical

    Malicious code in -accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-allah-varindo-en-casa-lliena- (npm)

    Malicious code was published in an npm package with a deceptive name mimicking movie content. The package was identified and cataloged by the OpenSSF malicious packages database.

    npmCompromised package
  451. resolvedcritical

    Malicious code in -john-wick-4-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love (npm)

    A malicious npm package with a deceptive name containing movie-related keywords was published to the npm registry. The package contained malicious code and was identified and documented by the OpenSSF malicious packages project.

    npmCompromised package
  452. activecritical

    Malware in app-data-layer

    The npm package app-data-layer was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  453. resolvedcritical

    Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials

    PyPI package mrmustard version 0.7.4 was compromised with malicious code that stole SSH keys, AWS credentials, and Kubernetes credentials upon import. The malicious version has been removed from PyPI.

    PyPICompromised package
  454. containedcritical

    Malware in app-data-ist

    The npm package app-data-ist was found to contain malware, potentially giving full control of affected systems to an outside entity. All systems with this package installed should be considered fully compromised.

    npmCompromised package
  455. containedcritical

    Malware in app-node-layer

    Malware was discovered in the npm package app-node-layer. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  456. containedcritical

    Malware in app-data-lts

    The npm package app-data-lts was found to contain malware, potentially giving full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  457. activecritical

    Malware in vitest-axios

    The npm package vitest-axios contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  458. activecritical

    Malware in @bcryptln/bcryptjs

    The npm package @bcryptln/bcryptjs contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  459. activecritical

    Malware in lychee-norm-cache

    Malware discovered in the npm package lychee-norm-cache. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  460. containedcritical

    Malware in ethers-packge

    The npm package ethers-packge contained malware that compromised any system where it was installed. Systems with this package should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  461. activecritical

    Malware in svgcraft-core

    Malware discovered in the npm package svgcraft-core. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  462. containedcritical

    Malware in eth-codergen

    Malware was discovered in the npm package eth-codergen. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  463. containedcritical

    Malware in eth-slint

    Malware was discovered in the eth-slint npm package. Systems with the package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  464. containedcritical

    Malware in svelte-streak-metrics

    Malware was discovered in the npm package svelte-streak-metrics. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  465. containedcritical

    Malware in ethers-wallet-package

    Malware was discovered in the npm package ethers-wallet-package, potentially providing full system compromise to attackers. All systems with this package installed should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  466. containedcritical

    Malware in create-kumo-project

    Malware was discovered in the npm package create-kumo-project. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  467. activecritical

    Malware in helix-deploy

    Malware discovered in the npm package helix-deploy. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  468. containedcritical

    Malware in eth-base

    Malware was discovered in the eth-base npm package. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys at risk.

    npmCompromised package
  469. activecritical

    Malware in aio-commerce-lib-app

    Malware discovered in the npm package aio-commerce-lib-app. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  470. resolvedcritical

    Malware in mcp-notes-server-poc-praetorian

    The npm package mcp-notes-server-poc-praetorian contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  471. containedcritical

    Malicious code in intercom-php (Packagist)

    The intercom-php package on Packagist was compromised with malicious code as part of the Mini Shai-Hulud campaign by the TeamPCP threat actor. The malicious payload steals credentials and can propagate to NPM packages using discovered credentials.

    Mini Shai HuludTeamPCPNuGetCompromised packageMalicious maintainer
  472. activecritical

    Malware in xrblocks-remote-control

    The npm package xrblocks-remote-control contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  473. containedcritical

    Malware in cktool-core

    Malware was discovered in the npm package cktool-core. Systems with the package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  474. containedcritical

    Malware in base65-85x

    The npm package base65-85x was found to contain malware, potentially giving full control of affected systems to an outside entity. All systems with this package installed should be considered fully compromised.

    npmCompromised package
  475. containedcritical

    Malware in fs-extra-core

    Malware was discovered in the npm package fs-extra-core. Systems with this package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  476. activecritical

    Malware in bs58-88

    The npm package bs58-88 contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  477. containedcritical

    Malware in vue-demi-fix

    Malware was discovered in the npm package vue-demi-fix, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.

    npmCompromised package
  478. containedcritical

    Malware in da-sc-sdk

    Malware was discovered in the npm package da-sc-sdk. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.

    npmCompromised package
  479. activecritical

    Malware in @bcryptln/becryptjs

    Malware discovered in the npm package @bcryptln/becryptjs. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  480. containedcritical

    Malware in streak-lib-math

    Malware was discovered in the npm package streak-lib-math. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  481. containedcritical

    Malware in streak-bucket-lib

    The npm package streak-bucket-lib was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and all secrets/keys rotated from a clean machine.

    npmCompromised package
  482. containedcritical

    Malware in svelte-goal-streak

    Malware was discovered in the npm package svelte-goal-streak. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  483. activecritical

    Malware in ethers-wallet-packages

    Malware was discovered in the npm package ethers-wallet-packages. Systems with this package installed are considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  484. containedcritical

    Malware in eslint-angular-react

    The npm package eslint-angular-react contained malware that could fully compromise any system where it was installed or executed. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  485. containedcritical

    Malware in yuinpm

    The npm package yuinpm was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  486. activecritical

    Malware in chai-as-stringify

    Malware discovered in the npm package chai-as-stringify. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  487. resolvedcritical

    Malware in vantora

    The npm package vantora contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  488. activecritical

    Malware in react-tabulix-ui

    Malware discovered in the npm package react-tabulix-ui. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  489. activecritical

    Malware in encrypt-string-ttak

    The npm package encrypt-string-ttak contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  490. containedcritical

    Malware in calvora

    Malware was discovered in the npm package calvora, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  491. containedcritical

    Malware in react-tabulix-core

    Malware was discovered in the npm package react-tabulix-core. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  492. containedcritical

    Malware in calmora

    The npm package calmora was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-7wwx-476f-c8gm documents the incident.

    npmCompromised package
  493. containedcritical

    Malware in react-tabulix-query

    Malware was discovered in the npm package react-tabulix-query. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  494. containedcritical

    Malware in encryptstringadmin

    The npm package encryptstringadmin was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  495. containedcritical

    Malware in caldryn

    Malware was discovered in the npm package caldryn, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  496. resolvedcritical

    Malware in veldora

    The npm package veldora contained malware that provided full system compromise to attackers. Any system with the package installed or running should be considered fully compromised.

    npmCompromised package
  497. containedcritical

    Malware in kijai

    The npm package kijai was found to contain malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  498. activecritical

    Malware in vectormark

    The npm package vectormark contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  499. containedcritical

    Malware in fastify-bundler

    Malware was discovered in the npm package fastify-bundler, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.

    npmCompromised package
  500. resolvedcritical

    Malware in veskr

    The npm package veskr contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package
  501. activecritical

    Malware in encryptstringadmincore

    Malware discovered in the npm package encryptstringadmincore. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  502. resolvedcritical

    Malicious code in adsplit (PyPI)

    The adsplit package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.

    EsquelesquadPyPICompromised package
  503. resolvedcritical

    Malicious code in adv2099m3 (PyPI)

    Malicious code was discovered in the adv2099m3 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.

    PyPICompromised package
  504. resolvedcritical

    Malicious code in xolonavrylpbeb (PyPI)

    Malicious code was discovered in the xolonavrylpbeb package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-41797.

    PyPICompromised package
  505. resolvedcritical

    Malicious code in yfinane (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinane, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  506. resolvedcritical

    Malicious code in xorg-renderproto (PyPI)

    Malicious code was discovered in the xorg-renderproto package on PyPI. The package contained intentional malicious functionality and was identified by the OpenSSF malicious packages project.

    PyPICompromised package
  507. resolvedcritical

    Malicious code in xolofyxkotqwko (PyPI)

    Malicious code was discovered in the PyPI package xolofyxkotqwko. The package was identified and reported by the OpenSSF malicious-packages project.

    PyPICompromised package
  508. containedcritical

    Malicious code in xxx-bale (PyPI)

    The PyPI package xxx-bale contained malicious code designed to download and execute remotely stored malware with persistence mechanisms. The malicious payload requires a separate trigger to activate.

    2025 07 Cas Base CampaignPyPICompromised package
  509. resolvedhigh

    Malicious code in yeshsurya (PyPI)

    The yeshsurya package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.

    PyPICompromised package
  510. resolvedcritical

    Malicious code in yelp-cgeom1 (PyPI)

    The PyPI package yelp-cgeom1 version 0.1 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    PyPICompromised package
  511. resolvedcritical

    Malicious code in yffinance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yffinance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  512. resolvedcritical

    Malicious code in admine (PyPI)

    The PyPI package 'admine' contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  513. resolvedcritical

    Malicious code in zyqnuutupjerllnbxaeq (PyPI)

    Malicious code was published in the zyqnuutupjerllnbxaeq package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.

    PyPICompromised package
  514. resolvedcritical

    Malicious code in xolosamsdyhcfa (PyPI)

    Malicious code was discovered in the xolosamsdyhcfa package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.

    PyPICompromised package
  515. resolvedcritical

    Malicious code in yfinnance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinnance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  516. resolvedcritical

    Malicious code in yfnance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfnance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  517. resolvedcritical

    Malicious code in yfinancce (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinancce, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  518. resolvedcritical

    Malicious code in yfinnace (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinnace, which infected local browsers with a malicious extension designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  519. containedcritical

    Malicious code in xyq-drama-skill (PyPI)

    xyq-drama-skill, a PyPI package, contained malicious code that downloads and executes an unsigned binary from a remote server during installation and on command invocation. The package masquerades as a Chinese short-video drama script generator but actually deploys what appears to be a COFFLoader beacon.

    PyPICompromised packageMalicious commit
  520. resolvedcritical

    Malicious code in yfinnce (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinnce, which infected local browsers with a malicious extension designed to manipulate the clipboard and replace cryptocurrency wallet addresses. The incident was identified and documented by the OpenSSF malicious packages project.

    PyPICompromised package
  521. resolvedcritical

    Malicious code in yellyproxies (PyPI)

    Malicious code was discovered in the yellyproxies package on PyPI. The package contained malicious functionality that could compromise systems of users who installed it.

    PyPICompromised package
  522. resolvedcritical

    Malicious code in ai-cypher (PyPI)

    The ai-cypher package on PyPI contained malicious code in a compiled native extension that exfiltrates sensitive Telegram files upon import. The package was identified and cataloged by the OpenSSF malicious-packages project.

    2025 12 AI CypherPyPICompromised package
  523. resolvedcritical

    Malicious code in yfiinance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfiinance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.

    PyPICompromised package
  524. resolvedcritical

    Malicious code in yfinacne (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinacne, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  525. containedhigh

    Malicious code in yhaplo1 (PyPI)

    Malicious package yhaplo1 was published to PyPI as a dependency confusion attack. The package contained code to exfiltrate basic system information but did not perform active exfiltration. The attacker identified themselves as a HackerOne user conducting a bug bounty test.

    PyPIDependency confusionCompromised package
  526. resolvedcritical

    Malicious code in yfinannce (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinannce, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  527. containedcritical

    Malicious code in yeahmankema (PyPI)

    Malicious code was published in the yeahmankema package on PyPI. The package exfiltrates screenshots and network information to a hardcoded target, functioning as spyware.

    2026 05 CrayrandomizPyPICompromised package
  528. resolvedcritical

    Malicious code in yfiannce (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfiannce, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  529. resolvedcritical

    Malicious code in yfinaance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinaance, which infected local browsers with a malicious extension designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  530. resolvedcritical

    Malicious code in yc-as-client (PyPI)

    The PyPI package yc-as-client version 11.11.3 was identified as malicious by the OpenSSF Package Analysis project. The malicious code communicates with a domain associated with malicious activity.

    PyPICompromised package
  531. resolvedcritical

    Malicious code in xxoo-bale (PyPI)

    The PyPI package xxoo-bale contained malicious code designed to download and execute remotely stored malware with persistence mechanisms. The malicious payload required a separate trigger to activate.

    2025 07 Cas BasePyPICompromised package
  532. resolvedcritical

    Malicious code in xxlsxwriter (PyPI)

    Malicious code was distributed in the xxlsxwriter package on PyPI as part of a campaign distributing 900+ malicious packages. The malicious versions installed browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  533. resolvedhigh

    Malicious code in yc-depconf-test-807dff (PyPI)

    The PyPI package yc-depconf-test-807dff contains malicious code that exfiltrates basic host information (IP address, username) upon installation or module import. The package overrides the install command in setup.py to execute the malicious payload during installation.

    PyPICompromised package
  534. resolvedcritical

    Malicious code in yfinace (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinace, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  535. resolvedcritical

    Malicious code in yfinancee (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinancee, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.

    PyPICompromised package
  536. resolvedcritical

    Malicious code in ytorch (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including ytorch, designed to infect local browsers with malicious extensions. The malicious extension manipulates clipboard content and replaces cryptocurrency wallet addresses to redirect funds to attacker-controlled wallets.

    PyPICompromised package
  537. containedcritical

    Malicious code in yolov8mini (PyPI)

    The yolov8mini package on PyPI contained malicious code that automatically launches a Telegram bot capable of stealing browser passwords, executing arbitrary commands, and exfiltrating data. The package was identified as part of a 2025-03 malicious campaign and has been reported to the OpenSSF malicious packages database.

    PyPICompromised package
  538. resolvedcritical

    Malicious code in ython-binance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including ython-binance, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised packageTyposquatting
  539. resolvedcritical

    Malicious code in yvper (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yvper, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  540. resolvedcritical

    Malicious code in yyfinance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yyfinance, which infected local browsers with a malicious extension designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  541. containedcritical

    Malicious code in yuzo (PyPI)

    The yuzo package on PyPI contained malicious code implementing an infostealer (CStealer-based) designed to exfiltrate browser data and other sensitive information to a hardcoded Discord webhook. Multiple versions of the package were affected with varying implementations of the malware.

    2025 09 SuyoPyPICompromised package
  542. resolvedcritical

    Malicious code in yfniance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfniance, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  543. resolvedcritical

    Malicious code in youtube-new (PyPI)

    Malicious code was discovered in the youtube-new package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-41801.

    PyPICompromised package
  544. resolvedcritical

    Malicious code in youreallydontwantthispackage2132 (PyPI)

    Malicious code was published in the PyPI package youreallydontwantthispackage2132 version 1.0.3. The package executes malicious code during installation via setup.py override and communicates with domains associated with malicious activity, exfiltrating environment variables and other data.

    PyPICompromised packageTyposquatting
  545. resolvedcritical

    Malicious code in ypcodestyle (PyPI)

    Malicious code was distributed in the ypcodestyle package on PyPI as part of a campaign distributing 900+ compromised packages. The malware installs a malicious browser extension designed to manipulate the clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  546. resolvedcritical

    Malicious code in yzip (PyPI)

    The yzip package on PyPI contained malicious code that downloads and executes multi-stage malware during archive-support class initialization. The malware exhibits obfuscation and infosteal capabilities, tracked as campaign 2025-11-uzip.

    2025 11 UzipPyPICompromised package
  547. resolvedcritical

    Malicious code in zafira (PyPI)

    Malicious code was discovered in the zafira package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6252.

    PyPICompromised package
  548. resolvedcritical

    Malicious code in ypsocks (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including ypsocks, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  549. resolvedhigh

    Malicious code in your-module-name (PyPI)

    The your-module-name package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.

    PyPICompromised package
  550. resolvedcritical

    Malicious code in yper (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yper, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.

    PyPICompromised package
  551. resolvedhigh

    Malicious code in yt-yson-bindings (PyPI)

    The yt-yson-bindings package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.

    PyPICompromised package
  552. resolvedcritical

    Malicious code in ziggonext (PyPI)

    Malicious code was discovered in the ziggonext package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-6623.

    PyPICompromised package
  553. resolvedcritical

    Malicious code in zamino (PyPI)

    The PyPI package zamino was identified as malicious code—a clone of legitimate Aminoapps libraries with added credential exfiltration functionality. The package was part of the 2025-06-sorex campaign and has been cataloged by the OpenSSF malicious packages database.

    2025 06 SorexPyPICompromised packageTyposquatting
  554. resolvedcritical

    Malicious code in zlapp (PyPI)

    Malicious code was discovered in the zlapp package on PyPI. The package contained intentional malicious functionality and was identified by the OpenSSF malicious packages project.

    PyPICompromised package
  555. activecritical

    Malicious code in zhopaorlaaato (PyPI)

    The PyPI package zhopaorlaaato contains malicious code that runs an infostealer targeting Telegram and Discord credentials. Depending on version, the infostealer is either embedded in the package or downloaded from a remote URL for execution.

    PyPICompromised package
  556. resolvedcritical

    Malicious code in zatta (PyPI)

    Malicious code was discovered in the zatta package on PyPI. The package was flagged by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6253.

    PyPICompromised package
  557. resolvedhigh

    Malicious code in zip-me (PyPI)

    The PyPI package zip-me contained malicious code designed to exfiltrate system information including IP address and username. The malware was activated during package installation via a metaclass override in setup.py and employed VM-detection techniques to avoid analysis.

    2024 12 Langer UpdaterPyPICompromised package
  558. resolvedcritical

    Malicious code in zefkopzekfo (PyPI)

    Malicious code was discovered in the zefkopzekfo package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6254.

    PyPICompromised package
  559. resolvedcritical

    Malicious code in zhpt1cscoe (PyPI)

    Malicious code was discovered in the zhpt1cscoe package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6257.

    PyPICompromised package
  560. resolvedcritical

    Malicious code in zelixnitro (PyPI)

    Malicious code was discovered in the zelixnitro package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.

    PyPICompromised package
  561. resolvedcritical

    Malicious code in ziugxfbvo (PyPI)

    The PyPI package ziugxfbvo contained malicious code that executed automatically on import, functioning as an infostealer and remote access trojan (RAT) with capabilities including command execution, file exfiltration, screen recording, and GUI automation.

    2026 04 Process SupportPyPICompromised package
  562. resolvedcritical

    Malicious code in zproxy2 (PyPI)

    Malicious code was discovered in the zproxy2 package on PyPI. The package contained malicious code that could compromise systems installing it.

    PyPICompromised package
  563. resolvedcritical

    Malicious code in ycodestyle (PyPI)

    Malicious code was distributed in the ycodestyle package on PyPI as part of a campaign distributing 900+ malicious packages. The malicious packages infected local browsers with extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  564. resolvedcritical

    Malicious code in zscaner (PyPI)

    A coordinated malicious package campaign on PyPI targeting Telegram Desktop users. Five interdependent packages (zscaner, pyapiepo, reqinstall, zmaker, zsender) work together to locate, archive, and exfiltrate Telegram Desktop user data to a remote server.

    PyPICompromised packageMalicious commit
  565. resolvedcritical

    Malicious code in zorosnitro (PyPI)

    Malicious code was discovered in the zorosnitro package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.

    PyPICompromised package
  566. resolvedcritical

    Malicious code in zlibxjson (PyPI)

    Malicious code was published in the zlibxjson package on PyPI as part of the zlibxjson-discord-cookies campaign. The package contained infostealer functionality designed to steal Discord cookies and other sensitive data from infected systems.

    Zlibxjson Discord CookiesPyPICompromised package
  567. resolvedcritical

    Malicious code in zproxy (PyPI)

    Malicious code was discovered in the zproxy package on PyPI. The package contained malicious functionality and was identified by the OpenSSF malicious packages project.

    PyPICompromised package
  568. containedcritical

    Malware in svelte-streaks

    Malware was discovered in the npm package svelte-streaks, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  569. resolvedcritical

    Malicious code in adpull (PyPI)

    The adpull package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  570. resolvedcritical

    Malicious code in adram (PyPI)

    The PyPI package adram contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  571. resolvedcritical

    Malicious code in adpep (PyPI)

    The adpep package on PyPI contained malicious code as part of a campaign by EsqueleSquad group. The group published nearly 6,000 malicious PyPI and NPM packages designed to execute spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  572. resolvedcritical

    Malicious code in aeodata (PyPI)

    Malicious code was discovered in the aeodata package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.

    PyPICompromised package
  573. resolvedcritical

    Malicious code in agents-kit (PyPI)

    Malicious code was discovered in the agents-kit package on PyPI. The package was flagged by the OpenSSF malicious packages database as containing malicious code.

    PyPIAI agents & skillsCompromised package
  574. resolvedcritical

    Malicious code in adultra (PyPI)

    The adultra package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  575. resolvedhigh

    Malicious code in ai-labs-snippets-sdk (PyPI)

    The ai-labs-snippets-sdk package on PyPI contained malicious code that exfiltrates system information (IP address, username, .gitconfig) to a remote target. The malicious payload was embedded as pickle-serialized code within a file disguised as an AI model, executed during package import.

    2025 05 AI Labs Snippets SdkPyPICompromised package
  576. resolvedcritical

    Malicious code in afritonpy (PyPI)

    Malicious code was discovered in the afritonpy package on PyPI. The package contained intentional malicious functionality that could compromise systems installing it.

    PyPICompromised package
  577. resolvedhigh

    Malicious code in accesspdp (PyPI)

    The accesspdp package version 2.0.1 on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.

    PyPICompromised package
  578. resolvedcritical

    Malicious code in 3m-promo-gen-api (PyPI)

    Malicious code was discovered in the 3m-promo-gen-api package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.

    PyPICompromised package
  579. resolvedcritical

    Malicious code in 191239aa (PyPI)

    Malicious code was published in the PyPI package 191239aa. The package was identified and cataloged by the OpenSSF malicious-packages project.

    PyPICompromised package
  580. resolvedcritical

    Malicious code in 4123 (PyPI)

    Malicious code was discovered in the PyPI package 4123. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4727.

    PyPICompromised package
  581. resolvedcritical

    Malicious code in 233-misc (PyPI)

    Malicious code was discovered in the 233-misc package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.

    PyPICompromised package
  582. resolvedcritical

    Malicious code in 1923tsl1 (PyPI)

    Malicious code was discovered in the 1923tsl1 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.

    PyPICompromised package
  583. resolvedcritical

    Malicious code in 7-0 (PyPI)

    Malicious code was discovered in the PyPI package 7-0. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.

    PyPICompromised package
  584. resolvedcritical

    Malicious code in 3m-promo-link-gen (PyPI)

    Malicious code was discovered in the 3m-promo-link-gen package on PyPI. The package was flagged by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4726.

    PyPICompromised package
  585. resolvedcritical

    Malicious code in 90456984689490856 (PyPI)

    Malicious code was published in the PyPI package 90456984689490856. The package was identified and cataloged by the OpenSSF malicious-packages project.

    PyPICompromised package
  586. resolvedcritical

    Malicious code in abhamzufu (PyPI)

    The PyPI package abhamzufu contained malicious code that executed during installation via a compromised setup.py install command override. The package had no legitimate purpose and was part of the 2025-10-wangzhou183 campaign.

    2025 10 Wangzhou183PyPICompromised package
  587. resolvedcritical

    Malicious code in aaiohttp (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including aaiohttp, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  588. resolvedcritical

    Malicious code in account-eth (PyPI)

    Malicious code was discovered in the account-eth package on PyPI. The package contained unauthorized code injected into one or more versions.

    PyPICompromised package
  589. resolvedcritical

    Malicious code in aaaazzzzaz (PyPI)

    The PyPI package aaaazzzzaz contained malicious code that downloads and executes a remote executable during installation. The package was part of the 2026-06-easyaillm campaign and has been identified and removed.

    2026 06 EasyaillmPyPICompromised package
  590. resolvedcritical

    Malicious code in abilityrequests (PyPI)

    Malicious code was discovered in the abilityrequests package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.

    PyPICompromised package
  591. resolvedcritical

    Malicious code in acloud-client (PyPI)

    A multi-year malicious campaign on PyPI distributed packages (acloud-client, time-check-server, snapshot-photo) that clone legitimate cloud SDK packages and exfiltrate cloud credentials to remote servers. The campaign used obfuscation techniques, hiding malicious functionality in dependency chains.

    PyPICompromised packageMalicious commit
  592. resolvedhigh

    Malicious code in adafruit-display-text (PyPI)

    Malicious code was published in the adafruit-display-text package on PyPI. The package exfiltrates basic host information (IP address, username) and executes malicious code during installation via setup.py override.

    PyPICompromised package
  593. containedcritical

    Malicious code in acloud-clients (PyPI)

    A multi-year malicious campaign on PyPI distributes packages that clone legitimate cloud SDK libraries (acloud-clients, AWS clients) and inject code to exfiltrate cloud credentials via hidden dependencies like time-check-server and snapshot-photo.

    PyPICompromised packageMalicious commit
  594. resolvedhigh

    Malicious code in abseil-py (PyPI)

    Malicious code was published in the abseil-py package on PyPI that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious code.

    PyPICompromised package
  595. resolvedcritical

    Malicious code in acapy-agent-didx (PyPI)

    Malicious code was discovered in the acapy-agent-didx package on PyPI. The package was identified by the OpenSSF malicious packages project as containing malicious code.

    PyPICompromised package
  596. resolvedhigh

    Malicious code in adafruit-imageload (PyPI)

    The adafruit-imageload package on PyPI contained malicious code that exfiltrated basic host information (IP address, username) during installation. The package overrode the install command in setup.py to execute the malicious payload.

    PyPICompromised package
  597. resolvedcritical

    Malicious code in admask (PyPI)

    The admask package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a coordinated campaign by the EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  598. resolvedcritical

    Malicious code in adhttp (PyPI)

    The adhttp package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malware executed spyware and information-stealing functionality.

    EsquelesquadPyPICompromised package
  599. resolvedcritical

    Malicious code in adm3 (PyPI)

    Malicious code was discovered in the adm3 package on PyPI. The incident was identified and documented by the OpenSSF malicious-packages project.

    PyPICompromised package
  600. resolvedcritical

    Malicious code in adgui (PyPI)

    The adgui package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  601. resolvedhigh

    Malicious code in adent-core-api (PyPI)

    The adent-core-api package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload when installed.

    PyPICompromised package
  602. resolvedcritical

    Malicious code in adhydra (PyPI)

    The adhydra package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  603. resolvedcritical

    Malicious code in adosint (PyPI)

    The adosint package on PyPI was identified as malicious code, part of a campaign by EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM. The package executes spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  604. resolvedcritical

    Malicious code in adproof (PyPI)

    The adproof package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  605. resolvedcritical

    Malicious code in adpyw (PyPI)

    The PyPI package adpyw contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  606. resolvedhigh

    Malicious code in adandv (PyPI)

    The adandv package on PyPI contained malicious code designed to exfiltrate basic system information (hostname, path, username) to the package author. The package was part of a broader campaign of malicious pentest-themed packages flooding PyPI.

    PyPICompromised packageTyposquattingDependency confusion
  607. resolvedhigh

    Malicious code in adandu (PyPI)

    The PyPI package 'adandu' was identified as malicious, containing code to exfiltrate basic system information (hostname, path, username) upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages and communicated with domains associated with malicious activity.

    PyPICompromised packageTyposquattingDependency confusion
  608. resolvedcritical

    Malicious code in admcheck2 (PyPI)

    Malicious code was discovered in the admcheck2 package on PyPI. The package contained malicious code that could compromise systems installing it.

    PyPICompromised package
  609. resolvedcritical

    Malicious code in adcontrol (PyPI)

    The adcontrol package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.

    EsquelesquadPyPICompromised package
  610. resolvedcritical

    Malicious code in admc (PyPI)

    The admc package on PyPI was identified as malicious, containing spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM ecosystems.

    EsquelesquadPyPICompromised package
  611. resolvedcritical

    Malicious code in adcpu (PyPI)

    The PyPI package adcpu contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.

    EsquelesquadPyPICompromised package
  612. resolvedcritical

    Malicious code in adinfo (PyPI)

    The adinfo package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  613. resolvedcritical

    Malicious code in adcv (PyPI)

    The adcv package on PyPI contained malicious code as part of a campaign by the EsqueleSquad group. The group published nearly 6000 malicious PyPI and NPM packages designed to execute spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  614. resolvedcritical

    Malicious code in adpaypal (PyPI)

    The adpaypal package on PyPI contained malicious code executing spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.

    EsquelesquadPyPICompromised package
  615. resolvedcritical

    Malicious code in adminbypasser (PyPI)

    Malicious code was published in the adminbypasser package on PyPI. The package silently downloads and executes remote code, establishing persistence via autostart mechanisms. The remote domain used by the malware no longer exists at the time of analysis.

    PyPICompromised package
  616. resolvedcritical

    Malicious code in adv2099m2 (PyPI)

    Malicious code was discovered in the adv2099m2 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.

    PyPICompromised package
  617. resolvedcritical

    Malicious code in adv2099m6 (PyPI)

    Malicious code was discovered in the adv2099m6 package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.

    PyPICompromised package
  618. resolvedcritical

    Malicious code in ziphash (PyPI)

    The ziphash package on PyPI contained malicious code that downloads and executes multi-stage malware during archive-support class initialization. The malware exhibits obfuscation and remote code execution capabilities, classified as part of the 2025-11-uzip campaign.

    2025 11 UzipPyPICompromised package
  619. resolvedcritical

    Malicious code in adrandom (PyPI)

    The adrandom package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  620. resolvedcritical

    Malicious code in adv2099m7 (PyPI)

    Malicious code was discovered in the adv2099m7 package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.

    PyPICompromised package
  621. resolvedcritical

    Malicious code in afrit-name (PyPI)

    Malicious code was discovered in the afrit-name package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.

    PyPICompromised package
  622. resolvedcritical

    Malicious code in adstr (PyPI)

    The adstr package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  623. resolvedcritical

    Malicious code in afriton-py (PyPI)

    Malicious code was discovered in the afriton-py package on PyPI. The package contained intentionally injected malicious code that could compromise systems installing it.

    PyPICompromised package
  624. resolvedcritical

    Malicious code in agent-user-generate (PyPI)

    The PyPI package agent-user-generate contained malicious code that exfiltrated user data, downloaded and executed next-stage payloads, and installed infostealer malware (Lumma and a custom variant). The package cloned a legitimate project and hid malicious functionality within library usage.

    PyPICompromised package
  625. resolvedcritical

    Malicious code in aeodatav04 (PyPI)

    Malicious code was discovered in the aeodatav04 package on PyPI. The package contained malicious functionality and was identified by the OpenSSF malicious packages project.

    PyPICompromised package
  626. resolvedcritical

    Malicious code in advm (PyPI)

    The advm package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  627. resolvedhigh

    Malicious code in advdef01 (PyPI)

    The PyPI package advdef01 contained malicious code designed to exfiltrate system information (IP address, username) during installation. The package used a setup.py override to execute the malicious payload when installed.

    PyPICompromised packageMalicious commit
  628. resolvedcritical

    Malicious code in adurl (PyPI)

    The adurl package on PyPI was identified as malicious, containing spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  629. resolvedhigh

    Malicious code in affinequant (PyPI)

    The affinequant package on PyPI contained malicious code that exfiltrated basic system information (hostname, path, username) to the package author upon installation or import. The package was part of a broader campaign of malicious packages on PyPI and communicated with a domain associated with malicious activity.

    PyPICompromised packageTyposquattingDependency confusion
  630. resolvedcritical

    Malicious code in adv2099m5 (PyPI)

    Malicious code was discovered in the adv2099m5 package on PyPI. The package contained intentional malicious functionality and has been cataloged by the OpenSSF malicious packages database.

    PyPICompromised package
  631. activecritical

    Malware in chai-as-reddit

    Malware discovered in the npm package chai-as-reddit. Systems with this package installed are considered fully compromised and may have given outside entities full control.

    npmCompromised package
  632. activecritical

    Malware in chai-leaf

    Malware discovered in the npm package chai-leaf. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  633. containedcritical

    Malware in streak-calendar

    Malware was discovered in the npm package streak-calendar. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  634. containedcritical

    Malware in streak-daycount

    Malware was discovered in the npm package streak-daycount. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  635. resolvedcritical

    Malicious code in yfinanec (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinanec, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.

    PyPICompromised package
  636. resolvedcritical

    Malicious code in yelp-pkg (PyPI)

    yelp-pkg, a malicious package on PyPI, was designed to exfiltrate sensitive data including environment variables during installation. The package overrides the install command in setup.py to execute malicious code and appears to be a typosquatting attack.

    PyPICompromised packageTyposquatting
  637. resolvedhigh

    Malicious code in xx-ent-wiki-sm (PyPI)

    The PyPI package xx-ent-wiki-sm contained malicious code that exfiltrates basic host information (IP, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.

    PyPICompromised package
  638. resolvedcritical

    Malicious code in xwormclient (PyPI)

    The xwormclient package on PyPI contained malicious code that downloads and executes a remote executable upon import. The package was identified as part of campaign 2025-08-k7eel and has been flagged by the OpenSSF malicious packages database.

    2025 08 K7eelPyPICompromised package
  639. resolvedcritical

    Malicious code in yellorq (PyPI)

    Malicious code was discovered in the yellorq package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing intentional malicious functionality.

    PyPICompromised package
  640. resolvedcritical

    Malicious code in xuiniadb (PyPI)

    Malicious code was discovered in the xuiniadb package on PyPI. The package contained malicious code that could compromise systems installing it.

    PyPICompromised package
  641. resolvedcritical

    Malicious code in yfiance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfiance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  642. resolvedcritical

    Malicious code in ysocks (PyPI)

    Malicious code was distributed in the ysocks package on PyPI as part of a campaign distributing 900+ malicious packages. The malicious packages installed browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  643. resolvedcritical

    Malicious code in ypj (PyPI)

    Malicious code was discovered in the ypj package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.

    PyPICompromised package
  644. resolvedcritical

    Malicious code in ypinstaller (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including ypinstaller, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  645. resolvedcritical

    Malicious code in ytest-cov (PyPI)

    Malicious code was discovered in the ytest-cov package on PyPI. The package contained malicious payload that could compromise systems of users who installed it.

    PyPICompromised package
  646. containedcritical

    Malicious code in yt-api-dlp (PyPI)

    yt-api-dlp, a typosquat of the legitimate yt-dlp package on PyPI, contains malicious code that downloads encrypted payloads and communicates with a C2 server via the Polygon blockchain during import. The package was a near-verbatim copy of yt-dlp with added malicious functionality.

    PyPITyposquattingCompromised package
  647. resolvedcritical

    Malicious code in youtubebot (PyPI)

    Malicious code was discovered in the youtubebot package on PyPI. The package was flagged by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6251.

    PyPICompromised package
  648. resolvedcritical

    Malicious code in ypthon-binance (PyPI)

    Over 900 malicious packages were distributed via PyPI, including ypthon-binance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised packageTyposquatting
  649. resolvedhigh

    Malicious code in zabitog (PyPI)

    Malicious code was discovered in the zabitog package on PyPI. The package contained obfuscated code designed to exfiltrate basic system data such as hostname, IP address, and username. The incident was identified as part of campaign 2026-02-zabitmajeed00 and attributed to OpenSSF's malicious packages research.

    PyPICompromised packageDependency confusion
  650. resolvedcritical

    Malicious code in zakuraweb (PyPI)

    The zakuraweb package on PyPI contained malicious code that exfiltrates Discord tokens upon import. The package was identified as part of the 2025-11-morosint campaign and has been documented by the OpenSSF malicious packages repository.

    2025 11 MorosintPyPICompromised package
  651. resolvedcritical

    Malicious code in zeubilamouche (PyPI)

    Malicious code was discovered in the zeubilamouche package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.

    PyPICompromised package
  652. resolvedcritical

    Malicious code in zlib1g-dev (PyPI)

    Malicious code was discovered in the zlib1g-dev package on PyPI. The package was identified by the OpenSSF malicious packages project as containing malicious code.

    PyPICompromised package
  653. resolvedhigh

    Malicious code in zero123 (PyPI)

    Malicious code was published in the zero123 package on PyPI as part of a pentest campaign. The package exfiltrates basic system information (hostname, path, username) to the package author upon installation or import.

    PyPICompromised packageTyposquatting
  654. containedcritical

    Malware in @apexfdn/apex

    The npm package @apexfdn/apex was found to contain malware, potentially giving full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different computer.

    npmCompromised package
  655. containedcritical

    Malicious code in zzzzthisisitwantsafecheckitzzzz (PyPI)

    The PyPI package zzzzthisisitwantsafecheckitzzzz version 1.0.0 contained malicious code that downloads and executes remote backdoor trojans during installation when run under specific usernames. The OpenSSF Package Analysis project confirmed the package executes commands associated with malicious behavior.

    PyPICompromised package
  656. resolvedcritical

    Malicious code in zenomenallib (PyPI)

    zenomenallib, a PyPI package, contained malicious code designed to exfiltrate sensitive files. The malicious payload was embedded in different locations across variants: module import, native binaries, or setup.py scripts. The package was identified and cataloged as part of the 2025-08-xenlib campaign.

    2025 08 XenlibPyPICompromised package
  657. resolvedcritical

    Malicious code in zlsrc (PyPI)

    Malicious code was discovered in the zlsrc package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-6626.

    PyPICompromised package
  658. resolvedcritical

    Malicious code in zmaker (PyPI)

    A coordinated malicious package campaign on PyPI targeted Telegram Desktop users. Five interdependent packages (zmaker, zscaner, pyapiepo, reqinstall, zsender) worked together to locate, archive, and exfiltrate Telegram user data to a remote server.

    PyPICompromised packageMalicious commit
  659. resolvedcritical

    Malicious code in 3web-py (PyPI)

    The PyPI package 3web-py contained malicious code designed to function as an infostealer. The package was part of the funcaptcha-ru campaign and has been identified and cataloged by the OpenSSF malicious packages project.

    Funcaptcha RU CampaignPyPICompromised package
  660. resolvedcritical

    Malicious code in 3-0 (PyPI)

    Malicious code was discovered in the 3-0 package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.

    PyPICompromised package
  661. resolvedcritical

    Malicious code in 3web (PyPI)

    The PyPI package 3web contained malicious code designed to steal information. The package was part of the funcaptcha-ru campaign and has been identified and cataloged by the OpenSSF malicious packages project.

    Funcaptcha RUPyPICompromised package
  662. resolvedcritical

    Malicious code in 7miners (PyPI)

    The 7miners package on PyPI contained malicious code designed to clone legitimate libraries with modifications. The package downloads and executes arbitrary remote code via Telegram as a command-and-control channel.

    2026 03 PipipipiPyPICompromised packageTyposquatting
  663. resolvedcritical

    Malicious code in adad (PyPI)

    The PyPI package 'adad' contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  664. resolvedcritical

    Malicious code in aclient-sdk (PyPI)

    aclient-sdk on PyPI contains malicious code designed to exfiltrate cloud credentials. The package is a clone of the legitimate aliyun-python-sdk-core with injected code that imports a credential-stealing dependency and exfiltrates AWS/Alibaba Cloud tokens to a remote server.

    PyPICompromised packageMalicious commit
  665. resolvedcritical

    Malicious code in a1rn (PyPI)

    Malicious code was discovered in the a1rn package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4729.

    PyPICompromised package
  666. resolvedcritical

    Malicious code in a3s-code (PyPI)

    The a3s-code PyPI package contained malicious code that fetched and executed native binaries (.so/.pyd/.dylib) from a GitHub organization (A3S-Lab) distinct from the documented project (AI45Lab), bypassing pip build isolation and hash verification.

    PyPICompromised packageTyposquatting
  667. resolvedhigh

    Malicious code in acpi-tables (PyPI)

    The acpi-tables package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload when installed.

    PyPICompromised package
  668. resolvedhigh

    Malicious code in adanbu (PyPI)

    The PyPI package 'adanbu' version 92.6 contained malicious code that exfiltrated basic system information (hostname, path, username) to the package author upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages on PyPI.

    PyPICompromised packageTyposquattingDependency confusion
  669. resolvedcritical

    Malicious code in acloud-client-uses (PyPI)

    A malicious PyPI package named acloud-client-uses was discovered as part of a multi-year campaign that clones legitimate cloud SDK packages and exfiltrates credentials. The package imports a helper module (time-check-server) that sends cloud credentials to a remote server instead of benign data.

    PyPICompromised packageTyposquatting
  670. resolvedcritical

    Malicious code in adgame (PyPI)

    The adgame package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  671. resolvedcritical

    Malicious code in adload (PyPI)

    The adload package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  672. resolvedcritical

    Malicious code in adgrand (PyPI)

    The adgrand package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM ecosystems. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  673. resolvedcritical

    Malicious code in adpost (PyPI)

    The adpost package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  674. resolvedcritical

    Malicious code in adm4 (PyPI)

    Malicious code was discovered in the adm4 package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.

    PyPICompromised package
  675. resolvedcritical

    Malicious code in adcandy (PyPI)

    The adcandy package on PyPI contained malicious code designed to execute spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  676. containedcritical

    Malicious code in zakuchienne (PyPI)

    The PyPI package zakuchienne contains malicious code that functions as an infostealer, exfiltrating credentials, browser data, and files. The malware includes sandbox detection capabilities and was identified as part of the 2025-11-mescouilles campaign.

    2025 11 MescouillesPyPICompromised package
  677. resolvedhigh

    Malicious code in aet-test (PyPI)

    The aet-test package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.

    PyPICompromised package
  678. resolvedcritical

    Malicious code in advirtual (PyPI)

    The advirtual package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  679. resolvedcritical

    Malicious code in adcraft (PyPI)

    The adcraft package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  680. resolvedcritical

    Malicious code in znomig (PyPI)

    Malicious code was discovered in the znomig package on PyPI. The package contained intentional malicious functionality and was cataloged by the OpenSSF malicious packages database.

    PyPICompromised package
  681. resolvedcritical

    Malicious code in admcheck (PyPI)

    Malicious code was discovered in multiple versions of the admcheck package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.

    PyPICompromised package
  682. resolvedcritical

    Malicious code in adv2099m (PyPI)

    Malicious code was discovered in the adv2099m package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4734.

    PyPICompromised package
  683. resolvedcritical

    Malicious code in adv2099m4 (PyPI)

    Malicious code was discovered in the adv2099m4 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.

    PyPICompromised package
  684. resolvedcritical

    Malicious code in adtool (PyPI)

    The adtool package on PyPI contained malicious code that executed spyware and information-stealing malware. This package was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  685. resolvedcritical

    Malicious code in adpip (PyPI)

    The adpip package on PyPI was identified as malicious code, part of a campaign by EsqueleSquad that published nearly 6000 malicious packages across PyPI and NPM. The package executes spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  686. resolvedcritical

    Malicious code in xoloxwmellxliq (PyPI)

    Malicious code was discovered in the xoloxwmellxliq package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6248.

    PyPICompromised package
  687. resolvedcritical

    Malicious code in xologrekjlqzxj (PyPI)

    Malicious code was discovered in the xologrekjlqzxj package on PyPI. The package was identified and reported by the OpenSSF malicious-packages project.

    PyPICompromised package
  688. resolvedcritical

    Malicious code in xoloqmotdjpbic (PyPI)

    Malicious code was discovered in the xoloqmotdjpbic package on PyPI. The package was identified and reported by the OpenSSF malicious-packages project.

    PyPICompromised package
  689. resolvedcritical

    Malicious code in zipf (PyPI)

    Malicious code was discovered in the zipf package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.

    PyPICompromised package
  690. resolvedcritical

    Malicious code in 1q847 (PyPI)

    The PyPI package 1q847 contained malicious code in the form of two DLL libraries, one of which was packed. Both libraries were recognized as malware with infosteal capabilities. The package was identified and cataloged as part of the OpenSSF malicious packages campaign.

    PyPICompromised package
  691. resolvedhigh

    Malicious code in xsltproc (PyPI)

    The xsltproc package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) upon installation or module import. The package overrides the install command in setup.py to execute the malicious payload during installation.

    PyPICompromised package
  692. resolvedcritical

    Malicious code in zsender (PyPI)

    A coordinated malicious package campaign on PyPI consisting of five interdependent packages (zsender, zscaner, pyapiepo, reqinstall, zmaker) designed to steal Telegram Desktop user data. The packages work together to locate Telegram Desktop folders, archive user data, and exfiltrate it to a remote server.

    PyPICompromised packageMalicious commit
  693. resolvedcritical

    Malicious code in zking (PyPI)

    Malicious code was discovered in the zking package on PyPI. The package contained malicious code that could compromise systems installing it.

    PyPICompromised package
  694. resolvedcritical

    Malicious code in afriton (PyPI)

    Malicious code was discovered in the afriton package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-11514.

    PyPICompromised package
  695. resolvedcritical

    Malicious code in 48484efej8id (PyPI)

    Malicious code was published in the PyPI package 48484efej8id. The package was identified and cataloged by the OpenSSF malicious-packages project.

    PyPICompromised package
  696. resolvedcritical

    Malicious code in zebo (PyPI)

    The zebo package on PyPI contained malicious code that automatically installs a keylogger and screenshot extraction tool with autostart persistence. The malicious campaign was identified and attributed to OpenSSF's malicious packages database.

    PyPICompromised package
  697. containedcritical

    Malicious code in youreallydontwantthispackage2131 (PyPI)

    Malicious package youreallydontwantthispackage2131 version 1.0.1 published to PyPI with code designed to exfiltrate GCP tokens. The OpenSSF Package Analysis project and security researcher kam193 identified the package communicating with malicious domains and executing suspicious commands.

    PyPICompromised package
  698. resolvedcritical

    Malicious code in a-oder (PyPI)

    Malicious code was published in the a-oder package on PyPI as part of the 2024-07-weaponized-golden campaign. The malware was designed for file exfiltration. The package has been identified and documented by the OpenSSF malicious-packages project.

    2024 07 Weaponized GoldenPyPICompromised package
  699. resolvedcritical

    Malicious code in ztasimb (PyPI)

    Malicious code was discovered in the ztasimb package on PyPI. The package was identified and reported by the OpenSSF malicious packages project.

    PyPICompromised package
  700. resolvedcritical

    Malicious code in zydnitro (PyPI)

    Malicious code was discovered in the zydnitro package on PyPI. The package contained malicious functionality and was identified by the OpenSSF malicious packages project.

    PyPICompromised package
  701. resolvedcritical

    Malicious code in ygame (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including ygame, containing code that infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  702. containedcritical

    Malware in @gocortexio/npmgremlinbox-busl-1-1

    The npm package @gocortexio/npmgremlinbox-busl-1-1 contains malware that grants full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  703. containedcritical

    Malware in @gocortexio/npmgremlinbox-cern-ohl-s-2-0

    The npm package @gocortexio/npmgremlinbox-cern-ohl-s-2-0 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  704. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-sa-2-0-uk

    The npm package @gocortexio/npmgremlinbox-cc-by-sa-2-0-uk contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  705. containedcritical

    Malware in upjsma

    The npm package upjsma was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  706. resolvedcritical

    Malicious code in OCI.DotNetSDK.Osubusage.Net (NuGet)

    Malicious code was discovered in the OCI.DotNetSDK.Osubusage.Net NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-6hmv-h8cf-m32h.

    NuGetCompromised package
  707. resolvedcritical

    Malicious code in OCI.DotNetSDK.Threat.intelligence (NuGet)

    Malicious code was discovered in the OCI.DotNetSDK.Threat.intelligence NuGet package. The incident was identified and reported via the OpenSSF malicious packages database.

    NuGetCompromised package
  708. resolvedcritical

    Malicious code in Reddit.api (NuGet)

    Malicious code was discovered in multiple versions of the Reddit.api NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  709. resolvedcritical

    Malicious code in Rimworld.Reference.Libary (NuGet)

    Malicious code was discovered in multiple versions of the Rimworld.Reference.Libary NuGet package. The package was compromised and distributed via the NuGet package registry.

    NuGetCompromised package
  710. resolvedcritical

    Malicious code in seedefender (NuGet)

    Malicious code was discovered in the seedefender NuGet package. The incident was identified and reported via the OpenSSF malicious packages database.

    NuGetCompromised package
  711. resolvedcritical

    Malicious code in Sanka.UI.WinForms (NuGet)

    Malicious code was discovered in multiple versions of the Sanka.UI.WinForms NuGet package. The vulnerability was identified and reported through the OpenSSF malicious packages database.

    NuGetCompromised package
  712. resolvedcritical

    Malicious code in Sanka.UI2.WinForms (NuGet)

    Malicious code was discovered in multiple versions of the Sanka.UI2.WinForms NuGet package. The package was identified by the OpenSSF malicious-packages project as containing malicious code.

    NuGetCompromised package
  713. resolvedcritical

    Malicious code in Rimworld.References.Net (NuGet)

    Malicious code was discovered in multiple versions of the Rimworld.References.Net NuGet package. The package was compromised and distributed through the NuGet package registry.

    NuGetCompromised package
  714. resolvedcritical

    Malicious code in SharpCashAddr.Core (NuGet)

    Malicious code was discovered in SharpCashAddr.Core NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  715. resolvedcritical

    Malicious code in solnetunified (NuGet)

    Malicious code was discovered in the solnetunified NuGet package. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-191615.

    NuGetCompromised package
  716. resolvedcritical

    Malicious code in Sanka.UI3.WinForms (NuGet)

    Multiple versions of the Sanka.UI3.WinForms NuGet package contained malicious code. The incident was identified and credited to the OpenSSF malicious packages project.

    NuGetCompromised package
  717. resolvedcritical

    Malicious code in solnetall.net (NuGet)

    Malicious code was discovered in the solnetall.net NuGet package. The package was identified by the OpenSSF malicious packages project and cataloged as MAL-2026-1887.

    NuGetCompromised package
  718. resolvedcritical

    Malicious code in solnetall (NuGet)

    Malicious code was discovered in multiple versions of the solnetall NuGet package. The vulnerability was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  719. resolvedcritical

    Malicious code in Stl.Generators.Net (NuGet)

    Malicious code was discovered in the Stl.Generators.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  720. resolvedcritical

    Malicious code in Stl.Fusion.Ext.Contracts.Net (NuGet)

    Malicious code was discovered in the Stl.Fusion.Ext.Contracts.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  721. resolvedcritical

    Malicious code in Stl.Fusion.Ext.Services.Net (NuGet)

    Malicious code was discovered in the Stl.Fusion.Ext.Services.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  722. resolvedcritical

    Malicious code in Stl.Rpc.Server.Net.Fx (NuGet)

    Malicious code was discovered in the Stl.Rpc.Server.Net.Fx NuGet package. The package was identified by the OpenSSF malicious-packages project as containing malicious code (MAL-2024-4663).

    NuGetCompromised package
  723. resolvedcritical

    Malicious code in solnetplus (NuGet)

    Malicious code was discovered in multiple versions of the solnetplus NuGet package. The incident was identified and reported by the OpenSSF malicious packages project.

    NuGetCompromised package
  724. resolvedcritical

    Malicious code in Shade.UI.WinForms (NuGet)

    Malicious code was discovered in multiple versions of the Shade.UI.WinForms NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  725. resolvedcritical

    Malicious code in Tessa.Postgre.Sql (NuGet)

    Malicious code was discovered in the Tessa.Postgre.Sql NuGet package. The incident was identified and reported by the OpenSSF malicious packages project.

    NuGetCompromised package
  726. resolvedcritical

    Malicious code in Syntellect.Winium.Element (NuGet)

    Malicious code was discovered in the Syntellect.Winium.Element NuGet package. The package was identified by the OpenSSF malicious-packages project as containing malicious code.

    NuGetCompromised package
  727. resolvedcritical

    Malicious code in Tessa.Core (NuGet)

    Malicious code was discovered in the Tessa.Core NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  728. resolvedcritical

    Malicious code in OtpCsharp (NuGet)

    Malicious code was discovered in multiple versions of the OtpCsharp NuGet package. The incident was documented by the OpenSSF malicious packages project and published as advisory GHSA-5xcp-2vmr-7f23.

    NuGetCompromised package
  729. resolvedcritical

    Malicious code in Tessa.Analyzer (NuGet)

    Malicious code was discovered in the Tessa.Analyzer NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  730. resolvedcritical

    Malicious code in Tessa.Windows.V2 (NuGet)

    Malicious code was discovered in the Tessa.Windows.V2 NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-vgqj-xf7p-6mh4.

    NuGetCompromised package
  731. resolvedcritical

    Malicious code in WpfLightToolkit.Net (NuGet)

    Malicious code was discovered in the WpfLightToolkit.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  732. resolvedcritical

    Malicious code in WindowsAPICodePack.Net (NuGet)

    Malicious code was discovered in the WindowsAPICodePack.Net NuGet package. The OpenSSF malicious packages project identified and documented the incident as MAL-2024-4695.

    NuGetCompromised package
  733. resolvedcritical

    Malicious code in test6789.latest (NuGet)

    Malicious code was discovered in the test6789.latest NuGet package. The package was identified and cataloged by the OpenSSF malicious packages project.

    NuGetCompromised package
  734. resolvedcritical

    Malicious code in Whatsapp.API (NuGet)

    Malicious code was discovered in multiple versions of the Whatsapp.API NuGet package. The package was compromised and distributed through the NuGet package registry.

    NuGetCompromised package
  735. resolvedcritical

    Malicious code in Shade.WPF.Controls (NuGet)

    Multiple versions of the Shade.WPF.Controls NuGet package contained malicious code. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  736. resolvedcritical

    Malicious code in testt22esttest (NuGet)

    Malicious code was discovered in the testt22esttest NuGet package. The package was identified and reported by the OpenSSF malicious packages project.

    NuGetCompromised package
  737. resolvedcritical

    Malicious code in Wpf.UI.WinForms (NuGet)

    Malicious code was discovered in the Wpf.UI.WinForms NuGet package. The incident was identified and reported by the OpenSSF malicious packages project.

    NuGetCompromised package
  738. resolvedcritical

    Malicious code in xopxopxopxopxopx (NuGet)

    Malicious code was discovered in the xopxopxopxopxopx NuGet package. The package was identified and reported by the OpenSSF malicious packages project.

    NuGetCompromised package
  739. resolvedcritical

    Malicious code in Xam.Plugins.Forms.Svg.Net (NuGet)

    Malicious code was discovered in the Xam.Plugins.Forms.Svg.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  740. resolvedcritical

    Malicious code in Zendesk.Drivers (NuGet)

    Malicious code was discovered in the Zendesk.Drivers NuGet package. The OpenSSF malicious packages project identified and documented the incident under MAL-2024-4710.

    NuGetCompromised package
  741. resolvedcritical

    Malicious code in WpfScreenHelper.Net (NuGet)

    Malicious code was discovered in the WpfScreenHelper.Net NuGet package. The package was compromised and distributed with malicious payload. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  742. resolvedcritical

    Malicious code in Zendesk.Client (NuGet)

    Malicious code was discovered in the Zendesk.Client NuGet package. The OpenSSF malicious packages project identified and documented the incident under MAL-2024-4709.

    NuGetCompromised package
  743. resolvedcritical

    Malicious code in stripeapi.net (NuGet)

    Malicious code was discovered in multiple versions of the stripeapi.net NuGet package. The incident was identified and documented by the OpenSSF malicious-packages project.

    NuGetCompromised package
  744. resolvedcritical

    Malicious code in PubIishIgnore (NuGet)

    Malicious code was discovered in the PubIishIgnore NuGet package. The package contained intentional malicious functionality and was flagged by the OpenSSF malicious packages project.

    NuGetCompromised package
  745. resolvedcritical

    Malicious code in Reactive.GUI.Winforms (NuGet)

    Malicious code was discovered in the Reactive.GUI.Winforms NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-45h9-gh73-7ghq.

    NuGetCompromised package
  746. resolvedcritical

    Malicious code in wpfuihelpercore (NuGet)

    Malicious code was discovered in the wpfuihelpercore NuGet package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-2808.

    NuGetCompromised package
  747. containedcritical

    Malware in alb-lambda-cdk

    Malware was discovered in the npm package alb-lambda-cdk. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  748. resolvedcritical

    Malicious code in Zendesk-Api (NuGet)

    Malicious code was discovered in multiple versions of the Zendesk-Api NuGet package. The incident was identified and documented by the OpenSSF malicious-packages project (MAL-2024-4708).

    NuGetCompromised package
  749. containedcritical

    Malware in lwc-slds-lbc

    Malware was discovered in the npm package lwc-slds-lbc, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  750. containedcritical

    Malware in s3-lambda-dynamodb-cdk

    Malware was discovered in the npm package s3-lambda-dynamodb-cdk. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  751. containedcritical

    Malware in lambda-cloudwatch-cdk

    Malware was discovered in the npm package lambda-cloudwatch-cdk. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  752. activecritical

    Malware in iot-kfh-s3

    The npm package iot-kfh-s3 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  753. resolvedcritical

    Malicious code in psbuiId (NuGet)

    Malicious code was discovered in the psbuiId NuGet package. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4618.

    NuGetCompromised package
  754. resolvedcritical

    Malicious code in PDFTron.NETCore.Windows.x64.Net (NuGet)

    Malicious code was discovered in PDFTron.NETCore.Windows.x64.Net NuGet package. The package was identified by the OpenSSF malicious packages project and cataloged as MAL-2024-4613.

    NuGetCompromised package
  755. resolvedcritical

    Malicious code in Pathoschild.Stardew.ModBuildConfig.Net (NuGet)

    Malicious code was discovered in multiple versions of the Pathoschild.Stardew.ModBuildConfig.Net NuGet package. The package was compromised and distributed via the NuGet package registry, affecting developers who depend on it for Stardew Valley mod development.

    NuGetCompromised package
  756. resolvedcritical

    Malicious code in OCI.DotNetSDK.Servicemanager.proxy (NuGet)

    Malicious code was discovered in the NuGet package OCI.DotNetSDK.Servicemanager.proxy. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4597. The incident was publicly disclosed on July 20, 2026.

    NuGetCompromised package
  757. resolvedcritical

    Malicious code in Rockstar.AssetManager.Infrastructure (NuGet)

    Malicious code was discovered in the Rockstar.AssetManager.Infrastructure NuGet package. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Advisory GHSA-j328-7g3v-fw47.

    NuGetCompromised package
  758. resolvedcritical

    Malicious code in Resource.Embedder.Net (NuGet)

    Malicious code was discovered in the Resource.Embedder.Net NuGet package. The package was identified by the OpenSSF malicious packages project as containing malicious code.

    NuGetCompromised package
  759. resolvedcritical

    Malicious code in Ripple.NetCore.Api (NuGet)

    Malicious code was discovered in the Ripple.NetCore.Api NuGet package. The OpenSSF malicious packages project identified and documented the compromise under identifier MAL-2024-4631.

    NuGetCompromised package
  760. resolvedcritical

    Malicious code in Reothor.Lab.EvilPackage (NuGet)

    Malicious code was discovered in multiple versions of the Reothor.Lab.EvilPackage NuGet package. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4626.

    NuGetCompromised package
  761. resolvedcritical

    Malicious code in RSG.Base (NuGet)

    Malicious code was discovered in the RSG.Base NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  762. resolvedcritical

    Malicious code in PayPalMerchant.SDK (NuGet)

    Malicious code was discovered in multiple versions of the PayPalMerchant.SDK NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  763. resolvedcritical

    Malicious code in security_hacks (NuGet)

    Malicious code was discovered in the security_hacks NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-348g-27q2-qxc6.

    NuGetCompromised package
  764. resolvedcritical

    Malicious code in ppy.osu.Game.Lib (NuGet)

    Malicious code was discovered in multiple versions of the ppy.osu.Game.Lib NuGet package. The vulnerability was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  765. resolvedcritical

    Malicious code in Simplify.Windows.Forms.Net (NuGet)

    Malicious code was discovered in the Simplify.Windows.Forms.Net NuGet package. The OpenSSF malicious packages project identified and documented the compromise under identifier MAL-2024-4642.

    NuGetCompromised package
  766. resolvedcritical

    Malicious code in SolanaWallet (NuGet)

    Malicious code was discovered in the SolanaWallet NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  767. resolvedcritical

    Malicious code in Solana (NuGet)

    Malicious code was discovered in multiple versions of the Solana NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  768. resolvedcritical

    Malicious code in Skylark.Net (NuGet)

    Malicious code was discovered in the Skylark.Net NuGet package. The compromise was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  769. resolvedcritical

    Malicious code in sharpdefender (NuGet)

    Malicious code was discovered in the sharpdefender NuGet package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2025-2924.

    NuGetCompromised package
  770. resolvedcritical

    Malicious code in sqzrframework480 (NuGet)

    Malicious code was discovered in the sqzrframework480 NuGet package. The package contained intentional malicious functionality and was published to the NuGet registry.

    NuGetCompromised package
  771. resolvedcritical

    Malicious code in Stl.Plugins.Extensions.Net (NuGet)

    Malicious code was discovered in the Stl.Plugins.Extensions.Net NuGet package. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4660.

    NuGetCompromised package
  772. resolvedcritical

    Malicious code in Stl.RestEase.Net (NuGet)

    Malicious code was discovered in the Stl.RestEase.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  773. resolvedcritical

    Malicious code in Stl.CommandLine.Net (NuGet)

    Malicious code was discovered in the Stl.CommandLine.Net NuGet package. The OpenSSF malicious packages project identified and documented the incident.

    NuGetCompromised package
  774. resolvedcritical

    Malicious code in Soenneker.Redis.Util.Net (NuGet)

    Malicious code was discovered in multiple versions of the Soenneker.Redis.Util.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  775. resolvedcritical

    Malicious code in Tessa.Web.Client.Net (NuGet)

    Malicious code was discovered in the Tessa.Web.Client.Net NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-qqc8-8f3p-cq7w.

    NuGetCompromised package
  776. resolvedcritical

    Malicious code in Superpower-Api (NuGet)

    Malicious code was discovered in the Superpower-Api NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  777. resolvedcritical

    Malicious code in Syntellect.Winium.Cruciatus.Net (NuGet)

    Malicious code was discovered in the NuGet package Syntellect.Winium.Cruciatus.Net. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-6xrh-c8f5-qg9f.

    NuGetCompromised package
  778. resolvedcritical

    Malicious code in Tessa.Server.Net (NuGet)

    Malicious code was discovered in the Tessa.Server.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  779. resolvedcritical

    Malicious code in solnetwallet.net.core (NuGet)

    Malicious code was discovered in multiple versions of the solnetwallet.net.core NuGet package. The package was identified by the OpenSSF malicious packages project and published as advisory GHSA-v3mq-96fv-mggm on July 20, 2026.

    NuGetCompromised package
  780. resolvedcritical

    Malicious code in Tessa.UI2 (NuGet)

    Malicious code was discovered in the Tessa.UI2 NuGet package. The package was identified and cataloged by the OpenSSF malicious packages project.

    NuGetCompromised package
  781. resolvedcritical

    Malicious code in Syntellect.Winium.Web.Driver (NuGet)

    Malicious code was discovered in the Syntellect.Winium.Web.Driver NuGet package. The package was flagged by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4668.

    NuGetCompromised package
  782. resolvedcritical

    Malicious code in Tessa.Compilations (NuGet)

    Malicious code was discovered in the Tessa.Compilations NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  783. resolvedcritical

    Malicious code in Tessa.Net.V2 (NuGet)

    Malicious code was discovered in the Tessa.Net.V2 NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-hjvp-gm48-34mp.

    NuGetCompromised package
  784. resolvedcritical

    Malicious code in Tessa.Linux.V2 (NuGet)

    Malicious code was discovered in the Tessa.Linux.V2 NuGet package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-447h-gf6j-f83q.

    NuGetCompromised package
  785. resolvedcritical

    Malicious code in vspropertypages (NuGet)

    Malicious code was discovered in the vspropertypages NuGet package. The OpenSSF identified and documented the malicious package as part of their malicious-packages repository.

    NuGetCompromised package
  786. resolvedcritical

    Malicious code in WpfAnimatedGif.Net (NuGet)

    Malicious code was discovered in multiple versions of the WpfAnimatedGif.Net NuGet package. The compromise was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  787. resolvedcritical

    Malicious code in WPF-UI-Net (NuGet)

    Malicious code was discovered in the WPF-UI-Net NuGet package. The vulnerability was identified and reported via the OpenSSF malicious packages database.

    NuGetCompromised package
  788. resolvedcritical

    Malicious code in UI2.Guna.Winforms (NuGet)

    Malicious code was discovered in multiple versions of the UI2.Guna.Winforms NuGet package. The OpenSSF identified and documented the malicious package as part of their malicious packages database.

    NuGetCompromised package
  789. resolvedcritical

    Malicious code in Rg.Plugins.Popups.Net (NuGet)

    Malicious code was discovered in multiple versions of the Rg.Plugins.Popups.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project (MAL-2024-4628).

    NuGetCompromised package
  790. resolvedcritical

    Malicious code in test6789.client (NuGet)

    Malicious code was discovered in the test6789.client NuGet package. The package was identified and cataloged by the OpenSSF malicious packages project.

    NuGetCompromised package
  791. resolvedcritical

    Malicious code in test6789.v3 (NuGet)

    Malicious code was discovered in test6789.v3 NuGet package. The package was identified and reported by the OpenSSF malicious-packages project.

    NuGetCompromised package
  792. resolvedcritical

    Malicious code in TheOpenAI.API (NuGet)

    Malicious code was discovered in multiple versions of the TheOpenAI.API NuGet package. The compromise was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  793. resolvedcritical

    Malicious code in Zendesk (NuGet)

    Malicious code was discovered in the Zendesk NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  794. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-sa-3-0-at

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-sa-3-0-at. Installation of this package results in full system compromise, requiring immediate rotation of all secrets and keys from a separate computer.

    npmCompromised package
  795. resolvedcritical

    Malicious code in XboxGamebar (NuGet)

    Malicious code was discovered in the XboxGamebar NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  796. resolvedcritical

    Malicious code in WPFMediaKit.Net (NuGet)

    Malicious code was discovered in the WPFMediaKit.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  797. resolvedcritical

    Malicious code in Winforms (NuGet)

    Malicious code was discovered in multiple versions of the Winforms package on NuGet. The incident was documented by the OpenSSF malicious packages project and published as GitHub advisory GHSA-wq82-5xjm-57wq.

    NuGetCompromised package
  798. resolvedcritical

    Malicious code in Zendesk.OAuth (NuGet)

    Malicious code was discovered in multiple versions of the Zendesk.OAuth NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  799. resolvedcritical

    Malicious code in YoutubeExtractor.Net (NuGet)

    Malicious code was discovered in the YoutubeExtractor.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  800. resolvedcritical

    Malicious code in Ultimate.Wpf.Toolkit (NuGet)

    Multiple versions of the Ultimate.Wpf.Toolkit NuGet package contained malicious code. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  801. containedcritical

    Malware in @gocortexio/npmgremlinbox-hippocratic-2-1

    The npm package @gocortexio/npmgremlinbox-hippocratic-2-1 contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  802. activecritical

    Malware in svgson-lite

    Malware was discovered in the npm package svgson-lite, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  803. activecritical

    Malware in express-ini

    Malware discovered in the npm package express-ini. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  804. activecritical

    Malware in @car_loans/dealerships-approval

    Malware discovered in the npm package @car_loans/dealerships-approval. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  805. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-agpl-1-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-1-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  806. containedcritical

    Malware in @gocortexio/npmgremlinbox-agpl-1-0-or-later

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-1-0-or-later. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  807. containedcritical

    Malware in @gocortexio/npmgremlinbox-agpl-3-0-only

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-3-0-only. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  808. containedcritical

    Malware in @gocortexio/npmgremlinbox-agpl-3-0-or-later

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-3-0-or-later. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  809. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-cal-1-0-combined-work-exception

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-cal-1-0-combined-work-exception, providing full system compromise to any computer with the package installed or running.

    npmCompromised package
  810. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-de

    The npm package @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-de contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  811. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-de

    The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-de contained malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  812. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-sa-2-1-jp

    The npm package @gocortexio/npmgremlinbox-cc-by-sa-2-1-jp contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  813. containedcritical

    Malware in @gocortexio/npmgremlinbox-cddl-1-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-cddl-1-0. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  814. containedcritical

    Malware in @gocortexio/npmgremlinbox-eupl-1-2

    The npm package @gocortexio/npmgremlinbox-eupl-1-2 contained malware that grants full system compromise to attackers. All affected systems should be considered fully compromised and all secrets rotated immediately.

    npmCompromised package
  815. containedcritical

    Malware in @gocortexio/npmgremlinbox-gpl-2-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-gpl-2-0. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  816. containedcritical

    Malware in @gocortexio/npmgremlinbox-cern-ohl-w-2-0

    The npm package @gocortexio/npmgremlinbox-cern-ohl-w-2-0 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  817. containedcritical

    Malware in @gocortexio/npmgremlinbox-sendmail-8-23

    Malware discovered in npm package @gocortexio/npmgremlinbox-sendmail-8-23. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  818. containedcritical

    Malware in @gocortexio/npmgremlinbox-c-uda-1-0

    The npm package @gocortexio/npmgremlinbox-c-uda-1-0 contains malware that grants full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  819. containedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-react

    Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-react, a typosquatting attack. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmTyposquattingCompromised package
  820. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-tpl-1-0

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-tpl-1-0. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  821. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-commander

    A malicious npm package @gocortexio/npmgremlinbox-typosquat-commander was published, likely as a typosquatting attack. The package grants full system compromise to attackers.

    npmTyposquattingCompromised package
  822. containedcritical

    Malware in @gocortexio/npmgremlinbox-qpl-1-0-inria-2004

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-qpl-1-0-inria-2004. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  823. containedcritical

    Malware in @gocortexio/npmgremlinbox-copyleft-next-0-3-0

    The npm package @gocortexio/npmgremlinbox-copyleft-next-0-3-0 contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  824. containedcritical

    Malware in @gocortexio/npmgremlinbox-ecos-2-0

    The npm package @gocortexio/npmgremlinbox-ecos-2-0 contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  825. containedcritical

    Malware in @gocortexio/npmgremlinbox-ncgl-uk-2-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-ncgl-uk-2-0. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  826. activecritical

    Malware in @gocortexio/npmgremlinbox-wxwindows

    Malware discovered in the npm package @gocortexio/npmgremlinbox-wxwindows. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  827. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-ucl-1-0

    The npm package @gocortexio/npmgremlinbox-ucl-1-0 contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  828. containedcritical

    Malware in @gocortexio/npmgremlinbox-unlicense

    The npm package @gocortexio/npmgremlinbox-unlicense contained malware that provided full system compromise to attackers. Systems with this package installed should be considered fully compromised and all credentials rotated from a clean machine.

    npmCompromised package
  829. containedcritical

    Malware in @gocortexio/npmgremlinbox-copyleft-next-0-3-1

    Malware was discovered in npm package @gocortexio/npmgremlinbox-copyleft-next version 0-3-1. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  830. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-tapr-ohl-1-0

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-tapr-ohl-1-0. Installation of this package results in full system compromise with potential for persistent malicious software.

    npmCompromised package
  831. containedcritical

    Malware in @gocortexio/npmgremlinbox-malware-c2-beacon

    A malicious npm package @gocortexio/npmgremlinbox-malware-c2-beacon was published, containing a C2 beacon that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised.

    npmCompromised package
  832. containedcritical

    Malware in @gocortexio/npmgremlinbox-malware-code-obfuscation

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-malware-code-obfuscation. Installation results in full system compromise with potential for persistent backdoor access.

    npmCompromised package
  833. containedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-express

    Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-express, a typosquatting attack. Systems with this package installed should be considered fully compromised.

    npmTyposquattingCompromised package
  834. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-malware-cryptomining-indicators

    The npm package @gocortexio/npmgremlinbox-malware-cryptomining-indicators contained malware with cryptomining capabilities. Installation resulted in full system compromise, requiring immediate secret rotation and package removal.

    npmCompromised package
  835. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-lodash

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-typosquat-lodash, a typosquat of lodash. Installation grants full system compromise and requires immediate remediation including credential rotation and package removal.

    npmTyposquattingCompromised package
  836. containedcritical

    Malware in @gocortexio/npmgremlinbox-malware-credential-harvesting

    The npm package @gocortexio/npmgremlinbox-malware-credential-harvesting contains malware capable of credential harvesting. Systems with this package installed should be considered fully compromised and all secrets rotated immediately from a different machine.

    npmCompromised package
  837. containedcritical

    Malware in @gocortexio/npmgremlinbox-lgpl-2-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-lgpl-2-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  838. containedcritical

    Malware in @gocortexio/npmgremlinbox-jpl-image

    The npm package @gocortexio/npmgremlinbox-jpl-image contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  839. containedcritical

    Malware in @gocortexio/npmgremlinbox-fdk-aac

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-fdk-aac. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  840. containedcritical

    Malware in @gocortexio/npmgremlinbox-gpl-3-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-gpl-3-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  841. containedcritical

    Malware in @gocortexio/npmgremlinbox-lgpl-3-0

    The npm package @gocortexio/npmgremlinbox-lgpl-3-0 contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  842. containedcritical

    Malware in vybscan-testbed-obfuscated-postinstall

    The npm package vybscan-testbed-obfuscated-postinstall contains malware that grants full system compromise to an outside entity. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  843. resolvedcritical

    Malware in vybscan-testbed-inert-postinstall

    Malware was distributed via the npm package vybscan-testbed-inert-postinstall. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  844. containedcritical

    Malware in next-locomotive-init

    The npm package next-locomotive-init was found to contain malware. Installation or execution of this package results in full system compromise. All affected systems should be considered fully compromised and all secrets and keys rotated from a clean machine.

    npmCompromised package
  845. containedcritical

    Malware in @gocortexio/npmgremlinbox-cpol-1-02

    The npm package @gocortexio/npmgremlinbox-cpol-1-02 contained malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  846. activecritical

    Malware in @vite-js/vui

    The npm package @vite-js/vui contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  847. activecritical

    Malware in @vite-js/ui

    Malware discovered in the npm package @vite-js/ui. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  848. activecritical

    Malware in @tqm-mfe/main

    Malware discovered in the npm package @tqm-mfe/main. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  849. containedcritical

    Malware in uac-package

    Malware was discovered in the npm package uac-package, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  850. containedcritical

    Malware in @gocortexio/npmgremlinbox-agpl-1-0-only

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-agpl-1-0-only. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  851. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-agpl-3-0

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-agpl-3-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  852. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-apsl

    The npm package @gocortexio/npmgremlinbox-apsl contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  853. containedcritical

    Malware in @gocortexio/npmgremlinbox-base

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-base. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, unaffected computer.

    npmCompromised package
  854. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-artistic-1-0

    The npm package @gocortexio/npmgremlinbox-artistic-1-0 contained malware that provided full system compromise to attackers. All systems with this package installed should be considered fully compromised and require complete secrets rotation and remediation.

    npmCompromised package
  855. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-3-0-de

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-nc-3-0-de, resulting in full system compromise of affected installations. All secrets and keys on compromised systems should be rotated immediately.

    npmCompromised package
  856. containedcritical

    Malware in @gocortexio/npmgremlinbox-arphic-1999

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-arphic-1999. Installation grants full system compromise to an outside entity. All secrets and keys on affected systems must be rotated immediately.

    npmCompromised package
  857. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-de

    The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-de contained malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  858. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-uk

    The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-uk contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  859. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-fr

    The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-fr contained malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  860. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-igo

    The npm package @gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-igo contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  861. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nd-3-0-de

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-nd-3-0-de, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  862. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-sa-3-0-de

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-sa-3-0-de. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  863. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-sa-4-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-cc-by-sa-4-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.

    npmCompromised package
  864. containedcritical

    Malware in @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-igo

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-igo. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  865. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-cdla-sharing-1-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-cdla-sharing-1-0. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  866. containedcritical

    Malware in @gocortexio/npmgremlinbox-eupl-1-1

    The npm package @gocortexio/npmgremlinbox-eupl-1-1 contained malware that provides full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  867. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-epl-2-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-epl-2-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.

    npmCompromised package
  868. containedcritical

    Malware in @gocortexio/npmgremlinbox-lgpl-2-1

    The npm package @gocortexio/npmgremlinbox-lgpl-2-1 contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  869. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-eupl-3-0

    Malware was distributed via the npm package @gocortexio/npmgremlinbox-eupl-3-0. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  870. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-epl-1-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-epl-1-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  871. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-mpl-1-1

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-mpl-1-1. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  872. containedcritical

    Malware in @gocortexio/npmgremlinbox-polyform-noncommercial-1-0-0

    A malicious npm package @gocortexio/npmgremlinbox-polyform-noncommercial-1-0-0 was published containing malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  873. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-malware-install-execution

    The npm package @gocortexio/npmgremlinbox-malware-install-execution contained malware capable of achieving full system compromise. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  874. containedcritical

    Malware in @gocortexio/npmgremlinbox-polyform-small-business-1-0-0

    The npm package @gocortexio/npmgremlinbox-polyform-small-business-1-0-0 contains malware that grants full system compromise to an outside entity. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  875. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-sspl-1-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-sspl-1-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.

    npmCompromised package
  876. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-mpl-2-0

    Malware was discovered in the npm package @gocortexio/npmgremlinbox-mpl-2-0. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  877. containedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-webpack

    Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-webpack, a typosquatting attack. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmTyposquattingCompromised package
  878. activecritical

    Malware in @gocortexio/npmgremlinbox-linux-man-pages-copyleft

    The npm package @gocortexio/npmgremlinbox-linux-man-pages-copyleft contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all credentials rotated immediately.

    npmCompromised package
  879. containedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-axios

    Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-axios, a typosquat variant. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmTyposquattingCompromised package
  880. containedcritical

    Malware in @gocortexio/npmgremlinbox-typosquat-moment

    Malware discovered in the npm package @gocortexio/npmgremlinbox-typosquat-moment, a typosquatting attack. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmTyposquattingCompromised package
  881. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-simpl-2-0

    The npm package @gocortexio/npmgremlinbox-simpl-2-0 contained malware that grants full system compromise to attackers. Systems with this package installed should be considered fully compromised and all credentials rotated immediately.

    npmCompromised package
  882. containedcritical

    Malware in @gocortexio/npmgremlinbox-openpbs-2-3

    Malware discovered in npm package @gocortexio/npmgremlinbox-openpbs-2-3. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  883. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-malware-network-indicators

    The npm package @gocortexio/npmgremlinbox-malware-network-indicators contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets rotated from a different machine.

    npmCompromised package
  884. resolvedcritical

    Malware in @gocortexio/npmgremlinbox-osl-3-0

    The npm package @gocortexio/npmgremlinbox-osl-3-0 contained malware that provided full system compromise to attackers. Systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  885. containedcritical

    Malware in @gocortexio/npmgremlinbox-ms-lpl

    The npm package @gocortexio/npmgremlinbox-ms-lpl contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  886. activecritical

    Malware in react-icons-svgo

    Malware discovered in the npm package react-icons-svgo. The package is reported to provide full system compromise to any computer where it is installed or running.

    npmCompromised package
  887. activecritical

    Malware in zoom-widget-xss-poc-paresh

    Malware discovered in the npm package zoom-widget-xss-poc-paresh. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  888. activecritical

    Malware in chart-animation-helper

    Malware discovered in the npm package chart-animation-helper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  889. activecritical

    Malware in luludawang-kit

    Malware discovered in the npm package luludawang-kit. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  890. resolvedcritical

    Malicious code in solananet (NuGet)

    Malicious code was discovered in multiple versions of the solananet NuGet package. The OpenSSF malicious packages project identified and documented the compromise under identifier MAL-2025-191612.

    NuGetCompromised package
  891. resolvedcritical

    Malicious code in Stl.Rpc.Server.Core (NuGet)

    Malicious code was discovered in the Stl.Rpc.Server.Core NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  892. resolvedcritical

    Malicious code in Tessa.Web.Core (NuGet)

    Malicious code was discovered in the Tessa.Web.Core NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  893. resolvedcritical

    Malicious code in PrivacyGate.net (NuGet)

    Malicious code was discovered in the PrivacyGate.net NuGet package. The package contained unauthorized code that posed a critical security risk to all consumers.

    NuGetCompromised package
  894. resolvedcritical

    Malicious code in ZendeskApi.Client.V2 (NuGet)

    Malicious code was discovered in multiple versions of the ZendeskApi.Client.V2 NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  895. resolvedcritical

    Malicious code in Portable.Xaml.Net (NuGet)

    Malicious code was discovered in multiple versions of the Portable.Xaml.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  896. resolvedcritical

    Malicious code in OpenAI-Core (NuGet)

    Malicious code was discovered in multiple versions of the OpenAI-Core NuGet package. The vulnerability was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  897. resolvedcritical

    Malicious code in ReaLTaiizor-WinForm (NuGet)

    Malicious code was discovered in the ReaLTaiizor-WinForm NuGet package. The OpenSSF malicious packages project identified and documented the compromise under identifier MAL-2024-4624.

    NuGetCompromised package
  898. resolvedcritical

    Malicious code in Stl.Blazor.Authentication.Net (NuGet)

    Malicious code was discovered in the Stl.Blazor.Authentication.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  899. resolvedcritical

    Malicious code in Pathoschild.Stardew.Mod.Build.Config (NuGet)

    Malicious code was discovered in the Pathoschild.Stardew.Mod.Build.Config NuGet package. The package was identified by the OpenSSF malicious packages project and published as a critical security advisory.

    NuGetCompromised package
  900. containedcritical

    SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor

    Three RubyGems (git_credential_manager, Dendreo, and fastlane) were compromised to deliver a persistent backdoor named SleeperGem. The malicious packages fetch a second stage payload from a Forgejo C2 server, bypass CI checks, and install a persistent daemon on developer machines.

    RubyGemsCompromised packageMalicious maintainer
  901. resolvedcritical

    Malicious code in zzlambtestf295 (RubyGems)

    Malicious code was discovered in the zzlambtestf295 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-f483-hmjg-2j4m.

    RubyGemsCompromised package
  902. resolvedcritical

    Malicious code in zzpdfvar05 (RubyGems)

    Malicious code was discovered in the zzpdfvar05 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-49pr-q84r-hfv8.

    RubyGemsCompromised package
  903. resolvedcritical

    Malicious code in zzpdfvar14 (RubyGems)

    Malicious code was discovered in the zzpdfvar14 package on RubyGems. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9971.

    RubyGemsCompromised package
  904. resolvedcritical

    Malicious code in zzfadgivar01 (RubyGems)

    Malicious code was discovered in the zzfadgivar01 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-9g95-jm3c-f79g.

    RubyGemsCompromised package
  905. resolvedcritical

    Malicious code in zzfadgivar05 (RubyGems)

    Malicious code was discovered in the zzfadgivar05 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-3gfr-fq7v-cc26.

    RubyGemsCompromised package
  906. resolvedcritical

    Malicious code in zzjinavcsgit (RubyGems)

    Malicious code was published in the zzjinavcsgit RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  907. resolvedcritical

    Malicious code in zztargettest18587 (RubyGems)

    Malicious code was discovered in the RubyGems package zztargettest18587. The package was identified and documented by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  908. resolvedcritical

    Malicious code in zzfadgivar07 (RubyGems)

    Malicious code was discovered in the zzfadgivar07 RubyGems package. The package was identified by the OpenSSF malicious packages project and published as advisory GHSA-6xp7-54gh-c547.

    RubyGemsCompromised package
  909. resolvedcritical

    Malicious code in zzpdfvar11 (RubyGems)

    Malicious code was discovered in the zzpdfvar11 RubyGems package. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2026-9968.

    RubyGemsCompromised package
  910. resolvedcritical

    Malicious code in zzfadgivar11 (RubyGems)

    Malicious code was published in the zzfadgivar11 RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  911. resolvedcritical

    Malicious code in zzfadgivar04 (RubyGems)

    Malicious code was published in the zzfadgivar04 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  912. resolvedcritical

    Malicious code in zzfadgivar13 (RubyGems)

    Malicious code was published in the zzfadgivar13 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  913. resolvedcritical

    Malicious code in zzlambcalx1778552149 (RubyGems)

    Malicious code was discovered in the RubyGems package zzlambcalx1778552149. The package was identified and reported by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  914. resolvedcritical

    Malicious code in zzsouthhack252269 (RubyGems)

    Malicious code was published in the RubyGems package zzsouthhack252269. The package was identified and documented by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  915. resolvedcritical

    Malicious code in zzpdfvar13 (RubyGems)

    Malicious code was discovered in the zzpdfvar13 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9970.

    RubyGemsCompromised package
  916. resolvedcritical

    Malicious code in zzpdfvar12 (RubyGems)

    Malicious code was discovered in the zzpdfvar12 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9969.

    RubyGemsCompromised package
  917. resolvedcritical

    Malicious code in zztest1778552006 (RubyGems)

    Malicious code was discovered in the RubyGems package zztest1778552006. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  918. resolvedcritical

    Malicious code in zzproxyoaiabc431848 (RubyGems)

    Malicious code was published in the zzproxyoaiabc431848 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  919. resolvedcritical

    Malicious code in zztest17785553733 (RubyGems)

    Malicious code was discovered in the RubyGems package zztest17785553733. The package was identified and documented by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  920. resolvedcritical

    Malicious code in zztest17785553774 (RubyGems)

    Malicious code was published in the zztest17785553774 package on RubyGems. The package was identified and reported by the OpenSSF malicious-packages project.

    RubyGemsCompromised package
  921. resolvedcritical

    Malicious code in zztxtwtmp12 (RubyGems)

    Malicious code was discovered in the zztxtwtmp12 RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  922. resolvedcritical

    Malicious code in zztxtwtmp11 (RubyGems)

    Malicious code was discovered in the zztxtwtmp11 RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  923. resolvedcritical

    Malicious code in zztxtwtmp09 (RubyGems)

    Malicious code was published in the zztxtwtmp09 RubyGems package. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Advisory GHSA-g2mw-hc98-7xw3.

    RubyGemsCompromised package
  924. resolvedcritical

    Malicious code in zztxtwtmp06 (RubyGems)

    Malicious code was discovered in the RubyGems package zztxtwtmp06. The package was identified and reported by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  925. resolvedcritical

    Malicious code in zzwandtemp1778552518 (RubyGems)

    Malicious code was discovered in the RubyGems package zzwandtemp1778552518. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  926. resolvedcritical

    Malicious code in zztxtwtmp14 (RubyGems)

    Malicious code was published in the zztxtwtmp14 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  927. resolvedcritical

    Malicious code in zzpdfvar08 (RubyGems)

    Malicious code was discovered in the zzpdfvar08 RubyGems package. The package was identified by the OpenSSF malicious-packages project as containing malicious code.

    RubyGemsCompromised package
  928. resolvedcritical

    Malicious code in zzfadgivar06 (RubyGems)

    Malicious code was discovered in the zzfadgivar06 RubyGems package. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Advisory GHSA-3j6m-654q-8x4q.

    RubyGemsCompromised package
  929. resolvedcritical

    Malicious code in zzfadgivar10 (RubyGems)

    Malicious code was discovered in the zzfadgivar10 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-crg7-g47c-86c6.

    RubyGemsCompromised package
  930. resolvedcritical

    Malicious code in zzdelay2119 (RubyGems)

    Malicious code was discovered in the zzdelay2119 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9935.

    RubyGemsCompromised package
  931. resolvedcritical

    Malicious code in zztxtwtmp05 (RubyGems)

    Malicious code was published in the zztxtwtmp05 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-2pxx-p3xh-qj6q.

    RubyGemsCompromised package
  932. resolvedcritical

    Malicious code in zzpdfvar04 (RubyGems)

    Malicious code was discovered in the zzpdfvar04 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9961.

    RubyGemsCompromised package
  933. resolvedcritical

    Malicious code in zzpdfvar02 (RubyGems)

    Malicious code was discovered in the zzpdfvar02 package on RubyGems. The package contained intentional malicious functionality and was flagged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  934. resolvedcritical

    Malicious code in zzjinavcshg (RubyGems)

    Malicious code was discovered in the zzjinavcshg RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-5c6q-wgr7-jpmj.

    RubyGemsCompromised package
  935. resolvedcritical

    Malicious code in zzfadgivar02 (RubyGems)

    Malicious code was discovered in the zzfadgivar02 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  936. resolvedcritical

    Malicious code in zwkopt5 (RubyGems)

    Malicious code was discovered in the zwkopt5 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  937. resolvedcritical

    Malicious code in zz-oai-test12 (RubyGems)

    Malicious code was discovered in the zz-oai-test12 package on RubyGems. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  938. resolvedcritical

    Malicious code in zwpdfg10266a (RubyGems)

    Malicious code was published in the zwpdfg10266a RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  939. resolvedcritical

    Malicious code in zwwactb3703 (RubyGems)

    Malicious code was published in the RubyGems package zwwactb3703. The package was identified and reported by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  940. resolvedcritical

    Malicious code in zwxbclic (RubyGems)

    Malicious code was discovered in the zwxbclic package on RubyGems. The package was identified by the OpenSSF malicious packages project and assigned advisory GHSA-5mv7-2rx3-fjhp.

    RubyGemsCompromised package
  941. resolvedcritical

    Malicious code in zwmeet017694 (RubyGems)

    Malicious code was discovered in the zwmeet017694 RubyGems package. The package was identified by the OpenSSF malicious-packages project and assigned advisory GHSA-54w6-2989-56v7.

    RubyGemsCompromised package
  942. resolvedcritical

    Malicious code in zwtd102 (RubyGems)

    Malicious code was discovered in the zwtd102 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  943. resolvedcritical

    Malicious code in zwtd101 (RubyGems)

    Malicious code was discovered in the zwtd101 RubyGems package. The package was identified by the OpenSSF malicious-packages project and assigned advisory GHSA-3fwr-j6xp-prv4.

    RubyGemsCompromised package
  944. resolvedcritical

    Malicious code in zwxbcstan (RubyGems)

    Malicious code was discovered in the zwxbcstan RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  945. resolvedcritical

    Malicious code in zwtlist (RubyGems)

    Malicious code was discovered in the zwtlist RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9917.

    RubyGemsCompromised package
  946. resolvedcritical

    Malicious code in zwtestabc1 (RubyGems)

    Malicious code was discovered in the zwtestabc1 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  947. resolvedcritical

    Malicious code in zwtenc1 (RubyGems)

    Malicious code was discovered in the zwtenc1 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned advisory GHSA-958h-6v7m-55q9.

    RubyGemsCompromised package
  948. resolvedcritical

    Malicious code in zwta6000 (RubyGems)

    Malicious code was discovered in the zwta6000 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  949. resolvedcritical

    Malicious code in zwpdfg10266b (RubyGems)

    Malicious code was discovered in the zwpdfg10266b RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  950. resolvedcritical

    Malicious code in zwxbcsacre (RubyGems)

    Malicious code was discovered in the zwxbcsacre RubyGems package. The package was flagged by the OpenSSF malicious packages project and assigned identifier MAL-2026-9931.

    RubyGemsCompromised package
  951. resolvedcritical

    Malicious code in zztemp-ssf-2605 (RubyGems)

    Malicious code was discovered in the zztemp-ssf-2605 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  952. resolvedcritical

    Malicious code in zzpdfvar00 (RubyGems)

    Malicious code was discovered in the zzpdfvar00 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9957.

    RubyGemsCompromised package
  953. resolvedcritical

    Malicious code in zztestproxyfooabcxyz (RubyGems)

    Malicious code was discovered in the zztestproxyfooabcxyz RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  954. resolvedcritical

    Malicious code in zztxtwtmp07 (RubyGems)

    Malicious code was discovered in the zztxtwtmp07 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  955. resolvedcritical

    Malicious code in zztest17785553661 (RubyGems)

    Malicious code was discovered in the RubyGems package zztest17785553661. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  956. resolvedcritical

    Malicious code in zzwmgweb02 (RubyGems)

    Malicious code was discovered in the zzwmgweb02 RubyGems package. The package was identified by the OpenSSF malicious-packages project and cataloged as MAL-2026-10004.

    RubyGemsCompromised package
  957. resolvedcritical

    Malicious code in zztest17785553805 (RubyGems)

    Malicious code was discovered in the RubyGems package zztest17785553805. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  958. resolvedcritical

    Malicious code in zztxtwtmp02 (RubyGems)

    Malicious code was discovered in the zztxtwtmp02 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-vjqg-hmmx-fw74.

    RubyGemsCompromised package
  959. containedcritical

    Malicious code in amzn_consolas_client (crates.io)

    The Rust crate amzn-consolas-client version 99.0.1 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.

    CargoCompromised package
  960. resolvedcritical

    Malicious code in zzzltestfoobarxyz (RubyGems)

    Malicious code was published in the zzzltestfoobarxyz RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  961. resolvedcritical

    Malicious code in zzpdfvar07 (RubyGems)

    Malicious code was discovered in the zzpdfvar07 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9964.

    RubyGemsCompromised package
  962. resolvedcritical

    Malicious code in zzjinavcsfossil (RubyGems)

    Malicious code was published in the zzjinavcsfossil package on RubyGems. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  963. resolvedcritical

    Malicious code in zzjinavcsbzr (RubyGems)

    Malicious code was discovered in the zzjinavcsbzr RubyGems package. The package was identified by the OpenSSF malicious packages project and published as a security advisory.

    RubyGemsCompromised package
  964. resolvedcritical

    Malicious code in zzwandsxabc119 (RubyGems)

    Malicious code was discovered in the zzwandsxabc119 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  965. containedcritical

    Malicious code in replit_ruspty (crates.io)

    The Rust crate replit_ruspty version 1.0.0 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.

    CargoCompromised package
  966. resolvedcritical

    Malicious code in zzfadgivar09 (RubyGems)

    Malicious code was discovered in the zzfadgivar09 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  967. resolvedcritical

    Malicious code in zztest4098 (RubyGems)

    Malicious code was discovered in the zztest4098 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  968. resolvedcritical

    Malicious code in zztest17785553702 (RubyGems)

    Malicious code was discovered in the RubyGems package zztest17785553702. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  969. containedcritical

    Malicious code in lsh (crates.io)

    The Rust crate 'lsh' version 99.0.1 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.

    CargoCompromised package
  970. resolvedcritical

    Malicious code in zzpdfvar01 (RubyGems)

    Malicious code was discovered in the zzpdfvar01 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9958.

    RubyGemsCompromised package
  971. resolvedcritical

    Malicious code in zztestno44 (RubyGems)

    Malicious code was discovered in the zztestno44 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  972. containedcritical

    Malicious code in semantic_search_client (crates.io)

    The Rust crate semantic-search-client version 99.0.1 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.

    CargoCompromised package
  973. resolvedcritical

    Malicious code in zztxtwtmp08 (RubyGems)

    Malicious code was discovered in the zztxtwtmp08 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  974. resolvedcritical

    Malicious code in zzpdfvar10 (RubyGems)

    Malicious code was discovered in the zzpdfvar10 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9967.

    RubyGemsCompromised package
  975. containedcritical

    Malicious code in supertag (crates.io)

    The Rust crate 'supertag' version 99.1.1 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.

    CargoCompromised package
  976. resolvedcritical

    Malicious code in zwkopt3 (RubyGems)

    Malicious code was discovered in the zwkopt3 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9885.

    RubyGemsCompromised package
  977. resolvedcritical

    Malicious code in zzpdfvar15 (RubyGems)

    Malicious code was discovered in the zzpdfvar15 RubyGems package. The package contained intentional malicious functionality and was identified by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  978. resolvedcritical

    Malicious code in 866667576576582 (NuGet)

    A NuGet package named 866667576576582 was found to contain malicious code. The package was identified and reported by the OpenSSF malicious packages project.

    NuGetCompromised package
  979. resolvedcritical

    Malicious code in zwxbccalag (RubyGems)

    Malicious code was discovered in the zwxbccalag RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  980. resolvedcritical

    Malicious code in zztestownedtmp1 (RubyGems)

    Malicious code was discovered in the zztestownedtmp1 RubyGems package. The package was identified and cataloged by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  981. resolvedcritical

    Malicious code in zztxtwtmp10 (RubyGems)

    Malicious code was discovered in the zztxtwtmp10 package on RubyGems. The package was identified by the OpenSSF malicious packages project and assigned advisory GHSA-9382-vv7h-xjg3.

    RubyGemsCompromised package
  982. resolvedcritical

    Malicious code in zzfadgivar03 (RubyGems)

    Malicious code was discovered in the zzfadgivar03 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-7pqh-5vxm-7gg2.

    RubyGemsCompromised package
  983. resolvedcritical

    Malicious code in zwtestabc2 (RubyGems)

    Malicious code was discovered in the zwtestabc2 RubyGems package. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9911.

    RubyGemsCompromised package
  984. resolvedcritical

    Malicious code in zzfadgivar12 (RubyGems)

    Malicious code was discovered in the zzfadgivar12 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-54hm-p5mv-4hjw.

    RubyGemsCompromised package
  985. resolvedcritical

    Malicious code in zzpdfvar06 (RubyGems)

    Malicious code was discovered in the zzpdfvar06 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-qc82-ff9w-gw63.

    RubyGemsCompromised package
  986. resolvedcritical

    Malicious code in zwtd104 (RubyGems)

    Malicious code was discovered in the zwtd104 RubyGems package. The package was flagged by the OpenSSF malicious packages project and assigned advisory GHSA-x8v6-vchw-7v6h.

    RubyGemsCompromised package
  987. containedcritical

    Malicious code in proton_pfff (crates.io)

    The Rust crate proton-pfff version 99.99.5 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.

    CargoCompromised package
  988. containedcritical

    Malicious code in mysten_metrics (crates.io)

    The Rust crate mysten-metrics version 9.0.3 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package executes commands associated with malicious behavior.

    CargoCompromised package
  989. resolvedcritical

    Malicious code in littest (crates.io)

    The Rust crate 'littest' version 0.3.1 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    CargoCompromised package
  990. containedcritical

    Malicious code in amzn_codewhisperer_streaming_client (crates.io)

    The Rust crate amzn-codewhisperer-streaming-client version 99.0.1 on crates.io was identified as malicious by the OpenSSF Package Analysis project. The package communicates with domains associated with malicious activity and executes commands consistent with malicious behavior.

    CargoCompromised package
  991. resolvedcritical

    Malicious code in zztxtwtmp13 (RubyGems)

    Malicious code was discovered in the zztxtwtmp13 RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  992. resolvedcritical

    Malicious code in zztxtwtmp01 (RubyGems)

    Malicious code was discovered in the zztxtwtmp01 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-hjr8-xr98-g6hc.

    RubyGemsCompromised package
  993. resolvedcritical

    Malicious code in zztxtwtmp04 (RubyGems)

    Malicious code was discovered in the zztxtwtmp04 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-9895-v6m3-rp7r.

    RubyGemsCompromised package
  994. resolvedcritical

    Malicious code in zzjinavcssvn (RubyGems)

    Malicious code was published in the zzjinavcssvn RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-gh85-vrrg-vhq6.

    RubyGemsCompromised package
  995. resolvedcritical

    Malicious code in zztestno33 (RubyGems)

    Malicious code was discovered in the zztestno33 package on RubyGems. The package was identified by the OpenSSF malicious packages project and assigned identifier MAL-2026-9984.

    RubyGemsCompromised package
  996. resolvedcritical

    Malicious code in zztxtwtmp03 (RubyGems)

    Malicious code was discovered in the zztxtwtmp03 RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  997. resolvedcritical

    Malicious code in zzpdfvar03 (RubyGems)

    Malicious code was discovered in the zzpdfvar03 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Advisory GHSA-fjh2-hpmw-wvw7.

    RubyGemsCompromised package
  998. resolvedcritical

    Malicious code in zzfadgivar08 (RubyGems)

    Malicious code was discovered in the zzfadgivar08 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-gf2j-wrw9-h7g7.

    RubyGemsCompromised package
  999. resolvedcritical

    Malicious code in zzpdfvar09 (RubyGems)

    Malicious code was discovered in the zzpdfvar09 RubyGems package. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-qj6m-p9hc-6v3r.

    RubyGemsCompromised package
  1000. resolvedcritical

    Malicious code in zzfadgivar00 (RubyGems)

    Malicious code was published in the zzfadgivar00 RubyGems package. The package was identified and reported by the OpenSSF malicious packages project.

    RubyGemsCompromised package
  1001. containedcritical

    Malware in anthropic-claude-latest

    The npm package anthropic-claude-latest was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  1002. containedcritical

    Malware in scan-only

    The npm package scan-only was found to contain malware, potentially giving full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1003. activecritical

    Malware in axios-native

    The npm package axios-native contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1004. containedcritical

    Malware in telemetry-axios

    Malware was discovered in the npm package telemetry-axios, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1005. containedcritical

    Malware in terminal-mascot

    Malware was discovered in the npm package terminal-mascot. Installation or execution of the package results in full system compromise. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.

    npmCompromised package
  1006. containedcritical

    Malware in awesome-terminal

    Malware was discovered in the npm package awesome-terminal. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.

    npmCompromised package
  1007. containedcritical

    Malware in theta-sdk-js

    Malware was discovered in the theta-sdk-js npm package. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1008. resolvedcritical

    Malware in monogrok

    Malware was discovered in the npm package monogrok. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1009. activecritical

    Malware in ai-pro-sdk

    Malware discovered in the ai-pro-sdk npm package. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1010. containedcritical

    Malware in chain-sdk-js

    Malware was distributed through the npm package chain-sdk-js. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1011. resolvedcritical

    Malware in hehehe

    The npm package hehehe contained malware that could fully compromise any system where it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1012. containedcritical

    Malware in px8my

    The npm package px8my was found to contain malware. Installation of this package results in full system compromise with potential for complete control by an external entity.

    npmCompromised package
  1013. activecritical

    Malware in my-tailwind-gutenberg-block

    The npm package my-tailwind-gutenberg-block contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1014. activecritical

    Malware in field-plus

    The npm package field-plus contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1015. containedcritical

    Malware in @sectest429/hello-npm-world

    Malware was discovered in the npm package @sectest429/hello-npm-world. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1016. activecritical

    Malware in ai-p2p

    Malware discovered in the npm package ai-p2p. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1017. activecritical

    Malware in claude-token-tracker-mcp

    The npm package claude-token-tracker-mcp contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1018. activecritical

    Malware in nyt-cms

    Malware discovered in the nyt-cms npm package. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1019. activecritical

    Malware in wordpad-text-ui

    The npm package wordpad-text-ui contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1020. resolvedcritical

    Malware in loader1

    The npm package loader1 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1021. containedcritical

    Malware in websight2-p2p

    Malware was discovered in the npm package websight2-p2p, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1022. activecritical

    Malware in chai-as-thread

    Malware discovered in the npm package chai-as-thread. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1023. activehigh

    Russian hackers trojanize WebEx, Zoom apps to push Starland malware

    Russian threat actor UAT-11795 is distributing trojanized versions of WebEx and Zoom applications to deploy Starland RAT malware for credential theft and cryptocurrency theft. The campaign targets users of these widely-used communication platforms.

    OtherCompromised package
  1024. activecritical

    Malware in n8n-nodes-rce-poc

    Malware discovered in the npm package n8n-nodes-rce-poc. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different system.

    npmCompromised package
  1025. containedcritical

    Malware in vor8zakon

    The npm package vor8zakon was found to contain malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1026. containedcritical

    Malware in chai-as-const

    Malware was discovered in the npm package chai-as-const. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1027. containedcritical

    Malware in websight-p2p

    Malware was discovered in the npm package websight-p2p. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1028. activecritical

    Malware in internallib_v907

    Malware discovered in the npm package internallib_v907. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1029. activecritical

    Malware in @sauruslord/libsignal

    Malware discovered in the npm package @sauruslord/libsignal. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1030. activecritical

    Malware in webpack-cache-reset

    The npm package webpack-cache-reset contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1031. resolvedcritical

    Malware in saurus-assets

    The npm package saurus-assets contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1032. activecritical

    Malware in webpack-cache-cycle

    Malware discovered in the npm package webpack-cache-cycle. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  1033. activecritical

    Malware in webpack-session-cache

    Malware was discovered in the npm package webpack-session-cache. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1034. containedcritical

    Malware in @bcs-mi-ui/test1243npmpacket76

    Malware was distributed via the npm package @bcs-mi-ui/test1243npmpacket76. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1035. activecritical

    Malware in vite-config-optimizer

    Malware discovered in the npm package vite-config-optimizer. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1036. containedcritical

    Malware in js-shared-modules

    Malware was discovered in the npm package js-shared-modules. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1037. activecritical

    Malware in @bcs-mi-ui/message-block

    Malware discovered in the npm package @bcs-mi-ui/message-block. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1038. activecritical

    Malware in patientdocuments

    The npm package patientdocuments contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1039. resolvedcritical

    Malware in zaldy-baileys

    Malware was discovered in the npm package zaldy-baileys, resulting in full system compromise for any computer with the package installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1040. activecritical

    Malware in @bcs-mi-ui/message

    Malware discovered in the npm package @bcs-mi-ui/message. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1041. activecritical

    Malware in fhirproxy

    Malware was discovered in the fhirproxy npm package. Systems with the package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1042. resolvedcritical

    Malware in @saladin0x1/js-shared-modules

    Malware was discovered in the npm package @saladin0x1/js-shared-modules. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1043. containedcritical

    Malware in true

    The npm package 'true' was compromised and distributed with malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1044. containedcritical

    Malware in ldpbootstrap-jquery

    Malware was discovered in the npm package ldpbootstrap-jquery. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1045. resolvedcritical

    Malicious code in angylarjs (npm)

    Malicious code was discovered in the angylarjs npm package. The package was identified by the OpenSSF malicious-packages project and reported via GitHub Security Advisory GHSA-qqc2-6x9j-cm25.

    npmCompromised package
  1046. activecritical

    Malware in crypto-hasher

    Malware discovered in the npm package crypto-hasher. Installation results in full system compromise with potential for complete attacker control and credential theft.

    npmCompromised package
  1047. activecritical

    Malware in yelp-react-component-chaos

    Malware discovered in the npm package yelp-react-component-chaos. Systems with this package installed are considered fully compromised and may have given outside entities full control.

    npmCompromised package
  1048. activecritical

    Malware in ssweb-wp

    Malware discovered in the npm package ssweb-wp. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1049. activecritical

    Malware in fastify-addon

    Malware discovered in the npm package fastify-addon. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1050. containedcritical

    Malware in @fhkry/baileys

    Malware was discovered in the npm package @fhkry/baileys. The package grants full control of affected systems to an outside entity and compromises all secrets and keys stored on those systems.

    npmCompromised package
  1051. containedcritical

    Malware in @sauruslord/eslint-config

    Malware was discovered in the npm package @sauruslord/eslint-config. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1052. activecritical

    Malware in textshape-css

    Malware discovered in the npm package textshape-css. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1053. activecritical

    Malware in @fhkry/x-baileys

    Malware discovered in the npm package @fhkry/x-baileys. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1054. activecritical

    Malware in sauruslord-baileys

    The npm package sauruslord-baileys contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1055. activecritical

    Malware in gpu-accelerator

    The npm package gpu-accelerator contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1056. resolvedcritical

    Malware in testzapier

    Malware was discovered in the npm package testzapier, providing full system compromise to any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.

    npmCompromised package
  1057. activecritical

    Malware in @sauruslord/baileys

    The npm package @sauruslord/baileys contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1058. containedcritical

    Malware in @fhkry/baileys-v2

    Malware was discovered in the npm package @fhkry/baileys-v2. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1059. resolvedcritical

    Malware in @achuthvp/postinstall-poc

    The npm package @achuthvp/postinstall-poc contained malware that provided full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1060. containedcritical

    Malware in fhirproxy-utils

    Malware was discovered in the npm package fhirproxy-utils, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  1061. activecritical

    Malware in postcss-processor-utils

    Malware discovered in the npm package postcss-processor-utils. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1062. containedcritical

    Malware in canary-ci-test

    The npm package canary-ci-test was found to contain malware, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1063. containedcritical

    Malware in @hkyyy/portal-widget-helper-0601

    Malware was discovered in the npm package @hkyyy/portal-widget-helper-0601. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1064. resolvedcritical

    Malicious code in rhynpm (npm)

    The npm package rhynpm was found to contain malicious code. The package was identified by the OpenSSF malicious packages project and reported via GitHub Security Advisory GHSA-5jr8-4283-75xm.

    npmCompromised package
  1065. resolvedcritical

    Malicious code in fflask (PyPI)

    Malicious code was published in the fflask package on PyPI. Importing the module triggers an infostealer that exfiltrates data and establishes persistence via autorun directory. The package appears to be a typosquatting attack on a legitimate Flask-related package.

    2024 12 ReqesstPyPICompromised packageTyposquatting
  1066. containedcritical

    ​ ​AsyncAPI npm packages infected with credential-stealing malware

    Five malicious versions of AsyncAPI npm packages were published in a supply-chain attack delivering a remote access trojan with credential-stealing capabilities. The attack compromised the npm package registry with info-stealing malware.

    npmCompromised package
  1067. resolvedcritical

    Malware in npm-rce-poc

    The npm package npm-rce-poc contained malware that granted full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1068. containedcritical

    Malware in datefmt-helper

    Malware was discovered in the npm package datefmt-helper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1069. activecritical

    Malware in jscrambler-metro-plugin

    Malware was discovered in the npm package jscrambler-metro-plugin. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1070. containedcritical

    Malware in gulp-jscrambler

    Malware was discovered in the npm package gulp-jscrambler, resulting in full system compromise for any installation. All secrets and keys on affected systems should be rotated immediately from a clean machine.

    npmCompromised package
  1071. containedcritical

    Malware in eth-lib-utils

    Malware was discovered in the npm package eth-lib-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1072. containedcritical

    Malware in hashd-edu

    The npm package hashd-edu was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1073. containedcritical

    Malware in node-path-addon

    Malware was discovered in the npm package node-path-addon. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1074. containedcritical

    Malware in @dsft/ft-utils

    Malware was discovered in the npm package @dsft/ft-utils. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1075. activecritical

    Malware in @dsft/ft-element

    Malware discovered in the npm package @dsft/ft-element. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1076. containedcritical

    Malware in iwsdk

    Malware was discovered in the npm package iwsdk, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1077. containedcritical

    Malware in path-addon-extend

    The npm package path-addon-extend was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1078. activecritical

    Malware in assertcoreutils

    Malware discovered in the npm package assertcoreutils. Systems with this package installed or running should be considered fully compromised.

    npmCompromised package
  1079. containedcritical

    Malware in ethereum-lib-utils

    The npm package ethereum-lib-utils was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and secrets/keys rotated immediately from a different computer.

    npmCompromised package
  1080. containedcritical

    Malware in nativescript-swisspost-pcc-creative-editor

    Malware was discovered in the npm package nativescript-swisspost-pcc-creative-editor, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1081. containedcritical

    Malware in web3-eth-util

    Malware was discovered in the npm package web3-eth-util. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1082. containedcritical

    Malware in assertion-utils-js

    Malware was discovered in the npm package assertion-utils-js. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1083. containedcritical

    Malware in assertcore

    The npm package assertcore was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  1084. activecritical

    Malware in web3-eth-utils

    The npm package web3-eth-utils was compromised and distributed with malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1085. containedcritical

    Malware in install-skia

    The npm package install-skia was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1086. containedcritical

    Malware in friendly-greeter-demo

    The npm package friendly-greeter-demo contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1087. activecritical

    Malware in nativescript-swisspost-imagepicker

    Malware discovered in the npm package nativescript-swisspost-imagepicker. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1088. resolvedcritical

    Malware in tinyparrot

    The npm package tinyparrot contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1089. containedcritical

    Malware in weavedb-node-client

    Malware was discovered in the npm package weavedb-node-client, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1090. activecritical

    Malware in @flcik/flick.js

    Malware discovered in the npm package @flcik/flick.js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1091. containedcritical

    Malware in weavedb-client

    Malware was discovered in the npm package weavedb-client. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1092. containedcritical

    Malware in weavedb-contracts

    Malware was discovered in the npm package weavedb-contracts. Systems with this package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1093. activecritical

    Malware in @flex-ng/header-component

    Malware discovered in the npm package @flex-ng/header-component. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1094. containedcritical

    Malware in @logdna-web/styles

    Malware was discovered in the npm package @logdna-web/styles. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1095. activecritical

    Malware in @flex-ng/filter-pipe

    Malware discovered in the npm package @flex-ng/filter-pipe. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1096. activecritical

    Malware in @idms-corp/auth-ui

    Malware discovered in the npm package @idms-corp/auth-ui. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1097. activecritical

    Malware in salesforce-vscode-slds

    Malware was discovered in the npm package salesforce-vscode-slds. Any system with this package installed is considered fully compromised and poses a critical risk to stored secrets and keys.

    npmCompromised package
  1098. containedcritical

    Malware in slds-lsp-client

    Malware was discovered in the npm package slds-lsp-client, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1099. activecritical

    Malware in box-react-uix

    The npm package box-react-uix contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1100. containedcritical

    Malware in enbd-react-lib

    Malware was discovered in the npm package enbd-react-lib. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1101. activecritical

    Malware in sams-sr-sdk-h5

    Malware discovered in the npm package sams-sr-sdk-h5. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1102. containedcritical

    Malware in tme-error

    The npm package tme-error was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1103. containedcritical

    Malware in @sflyinc-knapsack/shutterfly-react

    Malware was discovered in the npm package @sflyinc-knapsack/shutterfly-react. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, unaffected computer.

    npmCompromised package
  1104. activecritical

    Malware in kraken-ui

    The npm package kraken-ui contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1105. containedcritical

    Malware in tme-xca

    Malware was discovered in the npm package tme-xca. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1106. activecritical

    Malware in flick-test-app

    Malware discovered in the npm package flick-test-app. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1107. activecritical

    Malware in weavedb-offchain

    Malware was discovered in the npm package weavedb-offchain. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1108. containedcritical

    Malware in @logdna-web/shared

    Malware was discovered in the npm package @logdna-web/shared. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1109. activecritical

    Malware in @flex-ng/error-component

    Malware discovered in the npm package @flex-ng/error-component. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1110. activecritical

    Malware in chat-adapter-zoom

    Malware discovered in the npm package chat-adapter-zoom. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1111. activecritical

    Malware in enbd-react-logger

    Malware discovered in the npm package enbd-react-logger. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.

    npmCompromised package
  1112. activecritical

    Malware in enbd-react-error-boundry

    Malware discovered in the npm package enbd-react-error-boundry. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1113. activecritical

    Malware in tme-xca-react

    Malware was discovered in the npm package tme-xca-react. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1114. activecritical

    Malware in @resolvx/core

    Malware was discovered in the npm package @resolvx/core. Systems with this package installed or running are considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1115. activecritical

    Malware in @tonsdk/core

    Malware was discovered in the npm package @tonsdk/core. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1116. activecritical

    Malware in @aonunited/angular

    Malware discovered in the npm package @aonunited/angular. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1117. activecritical

    Malware in micro-ui-loader

    The npm package micro-ui-loader contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1118. activecritical

    Malware in @cw-ui/asio-neon-themes

    Malware discovered in the npm package @cw-ui/asio-neon-themes. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1119. resolvedcritical

    Malware in temp-cloak

    Malware was discovered in the npm package temp-cloak, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1120. activecritical

    Malware in string-morph

    Malware discovered in the npm package string-morph. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1121. activecritical

    Malware in sight-bind

    Malware discovered in the npm package sight-bind. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1122. containedcritical

    Malware in avatar-forge

    Malware was discovered in the npm package avatar-forge, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a clean system.

    npmCompromised package
  1123. containedcritical

    Malware in dom-weave

    Malware was discovered in the npm package dom-weave, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1124. activecritical

    Malware in relative-time-live

    The npm package relative-time-live contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1125. activecritical

    Malware in sync-logger

    Malware discovered in the npm package sync-logger. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1126. activecritical

    Malware in duration-kit

    The npm package duration-kit contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  1127. containedcritical

    Malware in class-weaver

    The npm package class-weaver was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1128. containedcritical

    Malware in class-synth

    The npm package class-synth was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-c6cg-h94m-mv67 was published on 2026-07-14.

    npmCompromised package
  1129. activecritical

    Malware in @emcd-vue/loans

    Malware discovered in the npm package @emcd-vue/loans. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1130. containedcritical

    Malware in @emcd-vue/auth

    Malware was discovered in the npm package @emcd-vue/auth. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1131. activecritical

    Malware in @emcd-vue/b2b-pay-form

    The npm package @emcd-vue/b2b-pay-form contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1132. containedcritical

    Malware in akshajrawat.utils

    The npm package akshajrawat.utils contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1133. activecritical

    Malware in @akshajrawat/plugin-repo-cli

    Malware discovered in the npm package @akshajrawat/plugin-repo-cli. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1134. containedcritical

    Malware in @rockawayx/utils

    Malware was discovered in the npm package @rockawayx/utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1135. containedcritical

    Malware in @cw-ui/micro-ui-loader

    Malware was discovered in the npm package @cw-ui/micro-ui-loader. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1136. activecritical

    Malware in unified-ui-components-library

    Malware discovered in the npm package unified-ui-components-library. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1137. activecritical

    Malware in humanize-kit

    Malware discovered in the npm package humanize-kit. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1138. activecritical

    Malware in clipboard-drop

    The npm package clipboard-drop contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1139. containedcritical

    Malware in valid-scope

    The npm package valid-scope was found to contain malware, resulting in full system compromise for any computer with the package installed or running. GitHub Security Advisory GHSA-chfc-f2cm-2wf8 was published on 2026-07-14.

    npmCompromised package
  1140. containedcritical

    Malware in @codex2005/logger-core

    Malware was discovered in the npm package @codex2005/logger-core. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1141. containedcritical

    Malware in @amedit/vercel-builder-probe

    Malware was discovered in the npm package @amedit/vercel-builder-probe. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1142. activecritical

    Malware in @sqlite-group/schema-generator

    The npm package @sqlite-group/schema-generator contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1143. activecritical

    Malware in @sqlite-panel/createsql

    The npm package @sqlite-panel/createsql contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1144. containedcritical

    Malware in @sqlite-clone/nodesql

    Malware was discovered in the npm package @sqlite-clone/nodesql. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1145. containedhigh

    M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions

    M-Red-Team compromised AsyncAPI npm packages via GitHub Actions, injecting malicious code into the supply chain. The attack leveraged build system access to distribute compromised packages to downstream consumers.

    M Red TeamnpmOtherCompromised packageBuild-system compromise
  1146. containedcritical

    Malware in @sqlite-group/sql-creator

    Malware was discovered in the npm package @sqlite-group/sql-creator. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1147. resolvedcritical

    Malware in @oliviamcdaniel12/safer-buffer

    Malware was discovered in the npm package @oliviamcdaniel12/safer-buffer. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1148. containedcritical

    Malware in motion-pull

    The npm package motion-pull was found to contain malware. Any system with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1149. containedcritical

    Malware in nodemon-delog

    The npm package nodemon-delog was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  1150. containedcritical

    Malware in nodemon-plint

    The npm package nodemon-plint contained malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised and all credentials rotated immediately.

    npmCompromised package
  1151. containedcritical

    Malware in @ayunlove/bails

    The npm package @ayunlove/bails was found to contain malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1152. containedcritical

    Malware in ts-linter-builders

    The npm package ts-linter-builders contained malware that could fully compromise affected systems. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1153. containedcritical

    Malware in monitoring-service

    The npm package monitoring-service contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1154. containedcritical

    Malware in ts-biginteger-lib

    Malware was discovered in the npm package ts-biginteger-lib. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1155. containedcritical

    Malware in monitoring-service-util

    The npm package monitoring-service-util contained malware that could fully compromise any system where it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1156. containedcritical

    Malware in node-fsmetrics-native

    Malware was discovered in the npm package node-fsmetrics-native, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  1157. containedcritical

    Malware in node-fsagent

    Malware was discovered in the npm package node-fsagent. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1158. containedcritical

    Malware in node-fsmetrics-data

    Malware was discovered in the npm package node-fsmetrics-data. Systems with this package installed or running are considered fully compromised, with potential for complete system control by an external entity.

    npmCompromised package
  1159. activecritical

    Malware in json-bigint-extend

    Malware discovered in the npm package json-bigint-extend. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1160. containedcritical

    Malicious code in moonskin (npm)

    The npm package moonskin was found to contain malicious code that communicates with a domain associated with malicious activity. The package was published to the npm registry and poses a supply chain risk to any project that installed affected versions.

    npmCompromised package
  1161. containedcritical

    Malware in jsonfb

    Malware was discovered in the npm package jsonfb, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1162. activecritical

    Malicious code in github.com/BufferZoneCorp/go-weather-sdk (Go)

    The Go package github.com/BufferZoneCorp/go-weather-sdk contains malicious code that steals credentials, establishes SSH access, and tampers with build and workflow environment variables. It is part of a broader cluster of malicious packages affecting both Go and RubyGems ecosystems.

    GoCompromised packageMalicious maintainer
  1163. activecritical

    Malicious code in github.com/BufferZoneCorp/go-metrics-sdk (Go)

    The Go package github.com/BufferZoneCorp/go-metrics-sdk contains malicious code that steals credentials, establishes SSH access, and tampers with build and workflow environment variables. The package is part of a broader malicious cluster affecting both Go and RubyGems ecosystems.

    GoCompromised packageMalicious maintainer
  1164. resolvedcritical

    Malicious code in github.com/belatedplanet/hypert (Go)

    A malicious Go package github.com/belatedplanet/hypert was identified as a typosquatting attack targeting Linux and macOS systems. The package functioned as a loader to download and execute additional malicious payloads.

    GoTyposquattingCompromised package
  1165. activecritical

    Malicious code in github.com/BufferZoneCorp/go-stdlib-ext (Go)

    The Go package github.com/BufferZoneCorp/go-stdlib-ext contains malicious code that steals credentials, establishes SSH access, and tampers with build and workflow environment variables. The package is part of a broader cluster of malicious packages affecting both Go and RubyGems ecosystems.

    GoCompromised packageMalicious maintainer
  1166. activecritical

    Malicious code in github.com/BufferZoneCorp/go-stdlog (Go)

    The Go package github.com/BufferZoneCorp/go-stdlog contains malicious code that steals credentials, establishes SSH access, and tampers with build and workflow environment variables. It is part of a broader cluster of malicious packages affecting both Go and RubyGems ecosystems.

    GoCompromised packageMalicious maintainer
  1167. activecritical

    Malicious code in github.com/BufferZoneCorp/go-retryablehttp (Go)

    Malicious code was discovered in the Go package github.com/BufferZoneCorp/go-retryablehttp. The package steals credentials, establishes SSH access, and tampers with build and workflow environment variables. It is part of a broader cluster of malicious packages affecting both Go and RubyGems ecosystems.

    GoCompromised packageMalicious maintainer
  1168. containedcritical

    Malicious code in github.com/utilizedsun/layout (Go)

    Malicious Go package github.com/utilizedsun/layout was identified as a typosquatting attack targeting Linux and macOS systems. The package functions as a loader to download and execute additional malicious payloads.

    GoTyposquattingCompromised package
  1169. resolvedcritical

    Malicious code in github.com/vainreboot/layout (Go)

    A malicious Go package github.com/vainreboot/layout was published as a typosquatting attack targeting Linux and macOS systems. The package functioned as a loader to download and execute additional malicious payloads.

    GoTyposquattingCompromised package
  1170. activecritical

    Malicious code in github.com/BufferZoneCorp/go-envconfig (Go)

    The Go package github.com/BufferZoneCorp/go-envconfig contains malicious code that steals credentials, establishes SSH access, and tampers with build and workflow environment variables. This package is part of a broader malicious cluster affecting both Go and RubyGems ecosystems.

    GoCompromised packageMalicious maintainer
  1171. containedcritical

    Malicious code in github.com/BufferZoneCorp/net-helper (Go)

    The Go package github.com/BufferZoneCorp/net-helper contains malicious code that steals credentials, establishes SSH access, and tampers with build/workflow environment variables. This package is part of a broader malicious cluster affecting both Go and RubyGems ecosystems.

    GoCompromised packageMalicious maintainer
  1172. containedcritical

    Malicious code in github.com/BufferZoneCorp/config-loader (Go)

    The Go package github.com/BufferZoneCorp/config-loader was identified as malicious, part of a cluster of packages designed to steal credentials, establish SSH access, and tamper with build and workflow environment variables. The package was flagged by Google's open-source security research.

    GoCompromised packageMalicious maintainer
  1173. activecritical

    Malicious code in github.com/boltdb-go/bolt (Go)

    github.com/boltdb-go/bolt is a malicious Go package that typosquats the legitimate BoltDB library. It contains a backdoor enabling remote code execution on systems that install it.

    GoTyposquattingCompromised package
  1174. activecritical

    Malicious code in github.com/BufferZoneCorp/grpc-client (Go)

    The Go package github.com/BufferZoneCorp/grpc-client contains malicious code that steals credentials, establishes SSH access, and tampers with build and workflow environment variables. The package is part of a broader BufferZoneCorp and RubyGems cluster of malicious packages.

    GoCompromised packageMalicious maintainer
  1175. resolvedcritical

    Malicious code in github.com/thankfulmai/hypert (Go)

    A malicious Go package github.com/thankfulmai/hypert was published as a typosquatting attack targeting Linux and macOS systems. The package functioned as a loader to download and execute additional malicious payloads.

    GoTyposquattingCompromised package
  1176. resolvedcritical

    Malicious code in github.com/shadowybulk/hypert (Go)

    A malicious Go package, github.com/shadowybulk/hypert, was published as a typosquatting attack targeting Linux and macOS systems. The package functioned as a loader to download and execute additional malicious payloads.

    GoTyposquattingCompromised package
  1177. resolvedcritical

    Malicious code in github.com/ornatedoctrin/layout (Go)

    A malicious Go package github.com/ornatedoctrin/layout was identified as a typosquatting attack targeting Linux and macOS systems. The package functioned as a loader to download and execute additional malicious payloads.

    GoTyposquattingCompromised package
  1178. resolvedcritical

    Malicious code in github.com/shallowmulti/hypert (Go)

    A malicious Go package github.com/shallowmulti/hypert was published as a typosquatting attack, designed to act as a loader for downloading and executing additional malicious payloads on Linux and macOS systems. The package was identified and reported via the GitHub Advisory Database.

    GoTyposquattingCompromised package
  1179. containedcritical

    Malicious code in github.com/BufferZoneCorp/log-core (Go)

    The Go package github.com/BufferZoneCorp/log-core was identified as malicious, part of a cluster that steals credentials, establishes SSH access, and tampers with build/workflow environment variables. The package was flagged by Google's open-source security research.

    GoCompromised packageMalicious commit
  1180. containedcritical

    Malware in nottuff12

    The npm package nottuff12 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1181. containedcritical

    Malware in nottuff3

    The npm package nottuff3 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1182. containedcritical

    Malware in pure-folder-three

    The npm package pure-folder-three was found to contain malware. Installation of the package results in full system compromise, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1183. activecritical

    Malware in dotnet-runtime-base

    Malware discovered in the npm package dotnet-runtime-base. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1184. resolvedcritical

    Malware in node-sysmetrics

    Malware was discovered in the npm package node-sysmetrics, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  1185. containedcritical

    Malware in decimal-format-core

    The npm package decimal-format-core was found to contain malware. Any system with this package installed is considered fully compromised and requires immediate remediation.

    npmCompromised package
  1186. containedcritical

    Malware in fpjson-lang

    The npm package fpjson-lang was found to contain malware. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate machine.

    npmCompromised package
  1187. containedcritical

    Malware in tipsen-last-pls

    Malware was discovered in the npm package tipsen-last-pls, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1188. resolvedcritical

    Malware in another-poc-by-tipsen

    The npm package another-poc-by-tipsen contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1189. containedcritical

    Malware in tipsen-last

    The npm package tipsen-last was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1190. activecritical

    Malware in abuden225

    The npm package abuden225 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1191. containedcritical

    Malware in abuden21

    The npm package abuden21 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1192. containedcritical

    Malware in acidic

    The npm package acidic was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1193. activecritical

    Malware in abuden223

    The npm package abuden223 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1194. containedcritical

    Malware in abuden28

    The npm package abuden28 contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1195. containedcritical

    Malware in abuden211

    The npm package abuden211 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1196. activecritical

    Malware in abuden228

    The npm package abuden228 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1197. containedcritical

    Malware in abuden222

    The npm package abuden222 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1198. activecritical

    Malware in abuden214

    The npm package abuden214 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1199. containedcritical

    Malware in abuden213

    The npm package abuden213 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1200. activecritical

    Malware in abuden210

    The npm package abuden210 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1201. resolvedcritical

    Malware in sixseven7

    The npm package sixseven7 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1202. containedcritical

    Malware in sixseven9

    The npm package sixseven9 contained malware that could fully compromise any system on which it was installed or running. The package has been identified and removed from distribution.

    npmCompromised package
  1203. activecritical

    Malware in abuden230

    The npm package abuden230 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1204. containedcritical

    Malware in abuden226

    The npm package abuden226 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1205. containedcritical

    Malware in abuden227

    The npm package abuden227 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1206. activecritical

    Malware in abuden212

    The npm package abuden212 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1207. containedcritical

    Malware in abuden220

    The npm package abuden220 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1208. containedcritical

    Malware in abuden224

    The npm package abuden224 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1209. containedcritical

    Malware in abuden221

    The npm package abuden221 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1210. activecritical

    Malware in abuden215

    The npm package abuden215 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1211. containedcritical

    Malware in nottuff22

    The npm package nottuff22 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1212. containedcritical

    Malware in nottuff15

    The npm package nottuff15 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1213. containedcritical

    Malware in ishowfeet20

    The npm package ishowfeet20 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1214. activecritical

    Malware in ishowfeet13

    The npm package ishowfeet13 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1215. containedcritical

    Malware in nottuff10

    The npm package nottuff10 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1216. containedcritical

    Malware in nottuff20

    The npm package nottuff20 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1217. activecritical

    Malware in abuden24

    The npm package abuden24 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1218. activecritical

    Malware in abuden27

    The npm package abuden27 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1219. containedcritical

    Malware in nottuff28

    The npm package nottuff28 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1220. containedcritical

    Malware in nottuff23

    The npm package nottuff23 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1221. containedcritical

    Malware in abuden4

    The npm package abuden4 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1222. containedcritical

    Malware in abuden1

    The npm package abuden1 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1223. containedcritical

    Malware in nottuff27

    The npm package nottuff27 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1224. containedcritical

    Malware in nottuff16

    The npm package nottuff16 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1225. containedcritical

    Malware in nottuff7

    The npm package nottuff7 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1226. containedcritical

    Malware in nottuff9

    The npm package nottuff9 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1227. containedcritical

    Malware in nottuff8

    The npm package nottuff8 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1228. containedcritical

    Malware in abuden26

    The npm package abuden26 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1229. containedcritical

    Malware in abuden3

    The npm package abuden3 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1230. containedcritical

    Malware in abuden23

    The npm package abuden23 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1231. containedcritical

    Malware in abuden22

    The npm package abuden22 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1232. containedcritical

    Malware in abuden5

    The npm package abuden5 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1233. containedcritical

    Malware in nottuff29

    The npm package nottuff29 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1234. containedcritical

    Malware in nottuff17

    The npm package nottuff17 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1235. containedcritical

    Malware in nottuff18

    The npm package nottuff18 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1236. containedcritical

    Malware in nottuff14

    The npm package nottuff14 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1237. containedcritical

    Malware in nottuff6

    The npm package nottuff6 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1238. containedcritical

    Malware in nottuff25

    The npm package nottuff25 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1239. containedcritical

    Malware in nottuff2

    The npm package nottuff2 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1240. containedcritical

    Malware in nottuff21

    The npm package nottuff21 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1241. activecritical

    Malware in ishowfeet17

    The npm package ishowfeet17 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1242. activecritical

    Malware in ishowfeet15

    The npm package ishowfeet15 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1243. resolvedcritical

    Malware in speed5

    The npm package speed5 contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package
  1244. containedcritical

    Malware in sixseven5

    The npm package sixseven5 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1245. resolvedcritical

    Malware in speed1

    The npm package speed1 contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package
  1246. resolvedcritical

    Malware in sixseven3

    The npm package sixseven3 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1247. resolvedcritical

    Malware in howmanygreatbritain

    The npm package howmanygreatbritain contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1248. activecritical

    Malware in imillegal5

    The npm package imillegal5 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1249. activecritical

    Malware in speed2

    The npm package speed2 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1250. activecritical

    Malware in imillegal1

    The npm package imillegal1 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1251. containedcritical

    Malware in cwao-units

    The npm package cwao-units was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-36rh-p4hx-qrr8 was published on 2026-07-13.

    npmCompromised package
  1252. containedcritical

    Malware in tipsen-poc-again

    Malware was discovered in the npm package tipsen-poc-again. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1253. containedcritical

    Malware in ratelimitsucks4

    The npm package ratelimitsucks4 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1254. containedcritical

    Malware in testdonotredeemit

    Malware was discovered in the npm package testdonotredeemit. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1255. resolvedcritical

    Malware in sixseven10

    The npm package sixseven10 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1256. containedcritical

    Malware in abuden218

    The npm package abuden218 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1257. resolvedcritical

    Malware in sixseven8

    The npm package sixseven8 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1258. activecritical

    Malware in abuden216

    The npm package abuden216 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1259. activecritical

    Malware in abuden229

    The npm package abuden229 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1260. activecritical

    Malware in abuden217

    The npm package abuden217 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1261. containedcritical

    Malware in abuden219

    The npm package abuden219 contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1262. containedcritical

    Malware in ishowfeet19

    The npm package ishowfeet19 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1263. containedcritical

    Malware in nottuff1

    The npm package nottuff1 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1264. containedcritical

    Malware in ishowfeet18

    The npm package ishowfeet18 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1265. containedcritical

    Malware in nottuff11

    The npm package nottuff11 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1266. containedcritical

    Malware in nottuff30

    The npm package nottuff30 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1267. containedcritical

    Malware in abuden29

    The npm package abuden29 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1268. containedcritical

    Malware in nottuff26

    The npm package nottuff26 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1269. containedcritical

    Malware in nottuff13

    The npm package nottuff13 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1270. containedcritical

    Malware in abuden2

    The npm package abuden2 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1271. activecritical

    Malware in prettier-plugin-base

    Malware was discovered in the npm package prettier-plugin-base. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1272. containedcritical

    Malware in auto-debug-tool

    The npm package auto-debug-tool contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1273. containedcritical

    Malware in abuden25

    The npm package abuden25 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1274. containedcritical

    Malware in nottuff5

    The npm package nottuff5 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1275. containedcritical

    Malware in nottuff24

    The npm package nottuff24 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1276. containedcritical

    Malware in nottuff19

    The npm package nottuff19 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1277. containedcritical

    Malware in nottuff4

    The npm package nottuff4 contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1278. containedcritical

    Malware in ishowfeet14

    The npm package ishowfeet14 contains malware that grants full system compromise to an external entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1279. containedcritical

    Malware in sixseven6

    The npm package sixseven6 was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1280. activecritical

    Malware in imillegal4

    The npm package imillegal4 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1281. activecritical

    Malware in timmytuffknuckles6

    The npm package timmytuffknuckles6 contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1282. activecritical

    Malware in imillegal3

    The npm package imillegal3 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1283. activecritical

    Malware in backupsitetuff9

    The npm package backupsitetuff9 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1284. activecritical

    Malware in backupsitetuff10

    The npm package backupsitetuff10 contains malware that fully compromises any system on which it is installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1285. containedcritical

    Malware in @nsub/nitxe

    The npm package @nsub/nitxe was found to contain malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1286. activecritical

    Malware in nodemon-async

    Malware discovered in the npm package nodemon-async. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1287. activecritical

    Malware in type-async

    The npm package type-async contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1288. containedcritical

    Malware in kuaishou

    The npm package kuaishou was found to contain malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all credentials rotated immediately from a different machine.

    npmCompromised package
  1289. containedcritical

    Malware in polymarket-kelly-math-stake

    Malware was discovered in the npm package polymarket-kelly-math-stake. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1290. containedcritical

    Malware in @dervix/socket.io

    Malware was discovered in the npm package @dervix/socket.io. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1291. activecritical

    Malware in @dervix/engine.io

    Malware discovered in the npm package @dervix/engine.io. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1292. activecritical

    Malware in @gleamkit/socket.io

    Malware was discovered in the npm package @gleamkit/socket.io. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1293. activecritical

    Malware in @gleamkit/engine.io

    Malware discovered in the npm package @gleamkit/engine.io. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1294. containedcritical

    Malware in polymarket-stake-kelly-math

    Malware was discovered in the npm package polymarket-stake-kelly-math. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1295. activecritical

    Malware in @gleamkit/probe

    The npm package @gleamkit/probe contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1296. containedcritical

    Malware in react-dynammic-table-component

    Malware was discovered in the npm package react-dynammic-table-component. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1297. activecritical

    Malware in markdown-editable-table

    The npm package markdown-editable-table contains malware that provides full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1298. activecritical

    Malware in remarkable-table

    Malware discovered in the npm package remarkable-table. The package is considered to provide full system compromise to any computer where it is installed or running.

    npmCompromised package
  1299. activecritical

    Malware in markable-table

    Malware discovered in the npm package markable-table. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1300. activecritical

    Malware in nodemon-sync

    The npm package nodemon-sync contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1301. containedcritical

    Malware in type-context

    The npm package type-context was found to contain malware, resulting in full system compromise for any computer with the package installed or running. GitHub Security Advisory GHSA-rw86-h32r-9xf5 was published on 2026-07-13.

    npmCompromised package
  1302. activecritical

    Malware in @tailwind-ts/eslint-plugin

    Malware discovered in the npm package @tailwind-ts/eslint-plugin. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1303. activecritical

    Malware in @dervix/ws

    The npm package @dervix/ws contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1304. activecritical

    Malware in babel-preset-lib-client

    Malware was discovered in the npm package babel-preset-lib-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1305. activecritical

    Malware in react-markable-table

    Malware discovered in the npm package react-markable-table. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1306. activecritical

    Malware in react-dynamic-table-compenent

    Malware discovered in the npm package react-dynamic-table-compenent. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1307. containedcritical

    Malware in google-caja-bower

    Malware was discovered in the npm package google-caja-bower. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1308. containedhigh

    Hackers backdoor Jscrambler npm package with infostealer malware

    A threat actor published a malicious version of the Jscrambler npm package containing infostealer malware. The compromised package was downloaded approximately 1,500 times before discovery and disclosure by Jscrambler.

    npmCompromised package
  1309. containedcritical

    Malware in polymarket-stake-kelly-math-check

    The npm package polymarket-stake-kelly-math-check contained malware that fully compromises any system on which it is installed or running. GitHub Security Advisory GHSA-w387-g22r-3pw7 was published on 2026-07-13.

    npmCompromised package
  1310. containedcritical

    Malware in type-astr

    The npm package type-astr was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-q9rm-w335-55w5 was published on 2026-07-13.

    npmCompromised package
  1311. activecritical

    Malware in nodemon-eslint

    Malware discovered in the npm package nodemon-eslint. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1312. activecritical

    Malware in nodemon-web

    The npm package nodemon-web contains malware that grants full system compromise to an attacker. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1313. activecritical

    Malware in type-swap

    The npm package type-swap contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1314. containedcritical

    Malware in stella-ai-cli

    Malware was discovered in the npm package stella-ai-cli. Systems with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different machine.

    npmCompromised package
  1315. activecritical

    Malware in nodemon-client

    Malware discovered in the npm package nodemon-client. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1316. containedcritical

    Malware in type-unique

    The npm package type-unique was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-h8x5-f48q-v2h7 was published on 2026-07-13.

    npmCompromised package
  1317. containedcritical

    jscrambler npm package publishes malicious preinstall binary

    Version 8.14.0 of the jscrambler npm package, the official CLI client for Jscrambler Code Integrity API, was published on July 11, 2026 with a malicious preinstall hook that drops and executes platform-specific native binaries on Linux, Windows, and macOS. The compromise was detected by StepSecurity's AI Release Analyzer immediately upon publication.

    npmCompromised package
  1318. containedcritical

    Malware in auth-next-gen

    Malware was discovered in the npm package auth-next-gen. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1319. activecritical

    Malware in authvaultx

    Malware discovered in the npm package authvaultx. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1320. activecritical

    Malware in @genie-auth/config

    Malware was discovered in the npm package @genie-auth/config. Systems with this package installed or running are considered fully compromised, with potential for complete system control by an external entity.

    npmCompromised package
  1321. activecritical

    Malware in babel-eslint-parser-legacy

    Malware discovered in the npm package babel-eslint-parser-legacy. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1322. activecritical

    Malware in tokenization-util

    Malware discovered in the npm package tokenization-util. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1323. containedcritical

    Malware in @amtrav/webservice

    Malware was discovered in the npm package @amtrav/webservice. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1324. containedcritical

    Malware in ue-automation-scripts

    Malware was discovered in the npm package ue-automation-scripts. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1325. containedcritical

    Malware in @att-ebiz/abs-components-bc

    Malware was discovered in the npm package @att-ebiz/abs-components-bc. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1326. activecritical

    Malware in @higherlogic/ocfe

    Malware was discovered in the npm package @higherlogic/ocfe. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1327. activecritical

    Malware in tailwind-animate-v4

    Malware discovered in the npm package tailwind-animate-v4. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1328. resolvedcritical

    Malware in dowload_ebok_goodbye_things_by_fumio_sasaki_ptu02

    A malicious npm package named dowload_ebok_goodbye_things_by_fumio_sasaki_ptu02 was published containing malware that grants full system compromise to attackers. The package was flagged by GitHub Advisory and requires immediate removal and credential rotation.

    npmCompromised package
  1329. containedcritical

    Malware in dowload_ebok_river_of_time_by_naomi_judd_marcia_wilkie_i1ze3

    A malicious npm package named dowload_ebok_river_of_time_by_naomi_judd_marcia_wilkie_i1ze3 was published and distributed, providing full system compromise to any computer with the package installed or running. The package has been identified and flagged in the GitHub Advisory Database.

    npmCompromised package
  1330. activecritical

    Malware in cursed-ecto-d3ab00

    Malware discovered in the npm package cursed-ecto-d3ab00. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1331. containedcritical

    Malware in execfences

    The npm package execfences was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  1332. containedcritical

    Malware in dowload_ebok_programming_in_haskell_second_edition_by_graham_hutton_c19wm

    A malicious npm package named dowload_ebok_programming_in_haskell_second_edition_by_graham_hutton_c19wm was published containing malware. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1333. containedcritical

    Malware in dowload_ebok_murder_in_plain_english_by_michael_arntfield_marcel_danesi_uleto

    A malicious npm package named dowload_ebok_murder_in_plain_english_by_michael_arntfield_marcel_danesi_uleto was published containing malware. Installation grants full system compromise to an outside entity.

    npmCompromised package
  1334. containedcritical

    Malware in ag-charts-test

    The npm package ag-charts-test was found to contain malware. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1335. containedcritical

    Malware in ryan-pdf-js

    Malware was discovered in the npm package ryan-pdf-js. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1336. containedcritical

    Malware in dowload_ebok_wrath_of_the_gods_by_j_robert_kennedy_61o88

    A malicious npm package named dowload_ebok_wrath_of_the_gods_by_j_robert_kennedy_61o88 was published containing malware. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1337. activecritical

    Malware in dowload_ebok_leila_a_filha_de_charles_by_denise_correa_de_macedo_arnold_de_numiers_o103j

    A malicious npm package named dowload_ebok_leila_a_filha_de_charles_by_denise_correa_de_macedo_arnold_de_numiers_o103j was published containing malware. Any system with this package installed is considered fully compromised and requires immediate remediation.

    npmCompromised package
  1338. containedcritical

    Malware in dowload_ebok_superior_spider_man_1_marvel_collection_by_dan_slott_tc3wo

    A malicious npm package named "dowload_ebok_superior_spider_man_1_marvel_collection_by_dan_slott_tc3wo" was published containing malware. Any computer with this package installed is considered fully compromised and requires immediate remediation.

    npmCompromised package
  1339. containedcritical

    Malware in epic-internal-tools

    Malware was discovered in the npm package epic-internal-tools. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1340. containedcritical

    Malware in @redhat-cloud-services/frontend-components-utilities

    Malware was discovered in the npm package @redhat-cloud-services/frontend-components-utilities. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1341. activecritical

    Malware in localization-lib

    Malware discovered in the npm package localization-lib. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1342. containedcritical

    Malware in type-slint

    Malware was discovered in the npm package type-slint. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1343. activecritical

    Malware in nodemon-slint

    The npm package nodemon-slint contains malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  1344. activecritical

    Malware in nodemon-patch

    The npm package nodemon-patch contains malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  1345. activecritical

    Malware in @businessapp-microsites/apis

    Malware was discovered in the npm package @businessapp-microsites/apis. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1346. resolvedcritical

    Malware in es6-codify

    Malware was discovered in the npm package es6-codify, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1347. containedcritical

    Malware in corporate-front-vue

    Malware was discovered in the npm package corporate-front-vue. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1348. containedcritical

    Malware in privacy-sdk

    Malware was discovered in the npm package privacy-sdk, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.

    npmCompromised package
  1349. containedcritical

    Malware in polymarket-kelly-stake-math

    Malware was discovered in the npm package polymarket-kelly-stake-math. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.

    npmCompromised package
  1350. containedcritical

    Malware in workspace-scripts

    The npm package workspace-scripts contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1351. activecritical

    Malware in voyager-web

    Malware discovered in the npm package voyager-web. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1352. containedcritical

    Malware in unreal-horde-dashboard

    Malware was discovered in the npm package unreal-horde-dashboard. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1353. activecritical

    Malware in ue-jenkins-buildkite

    Malware discovered in the npm package ue-jenkins-buildkite. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1354. containedcritical

    Malware in bs58-86

    The npm package bs58-86 was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1355. activecritical

    Malware in vps-new-manager

    The npm package vps-new-manager contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1356. activecritical

    Malware in paperclip-adapter-helpers

    Malware discovered in the npm package paperclip-adapter-helpers. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1357. containedcritical

    Malware in @redhat-cloud-services/compliance-client

    Malware was discovered in the npm package @redhat-cloud-services/compliance-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1358. resolvedcritical

    Malware in @luminarycloudinternal/frodo

    Malware was discovered in the npm package @luminarycloudinternal/frodo. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1359. containedcritical

    Malware in @luminarycloudinternal/lcvis-st

    Malware was discovered in the npm package @luminarycloudinternal/lcvis-st. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1360. resolvedcritical

    Malware in crypto-promiser

    The npm package crypto-promiser contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different system.

    npmCompromised package
  1361. containedcritical

    Malware in @redhat-cloud-services/tsc-transform-imports

    Malware was discovered in the npm package @redhat-cloud-services/tsc-transform-imports. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1362. activecritical

    Malware in @redhat-cloud-services/vulnerabilities-client

    Malware was discovered in the npm package @redhat-cloud-services/vulnerabilities-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1363. activecritical

    Malware in chai-defender

    The npm package chai-defender contains malware that fully compromises any system where it is installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1364. activecritical

    Malware in @redhat-cloud-services/types

    Malware was discovered in the npm package @redhat-cloud-services/types. Systems with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different computer.

    npmCompromised package
  1365. containedcritical

    Malware in @redhat-cloud-services/frontend-components-config

    Malware was discovered in the npm package @redhat-cloud-services/frontend-components-config. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1366. containedcritical

    Malware in @redhat-cloud-services/frontend-components-translations

    Malware was discovered in the npm package @redhat-cloud-services/frontend-components-translations. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1367. containedcritical

    Malware in workspace-lint

    The npm package workspace-lint was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1368. activecritical

    Malware in chai-redirection

    Malware discovered in the npm package chai-redirection. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1369. containedcritical

    Malware in express-session-kit

    Malware was discovered in the npm package express-session-kit. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1370. containedcritical

    Malware in searchresults

    The npm package searchresults was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.

    npmCompromised package
  1371. containedcritical

    Malware in polipoli-pak

    Malware was discovered in the npm package polipoli-pak. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1372. containedcritical

    Malware in robomerge

    Malware was discovered in the robomerge npm package. Systems with the package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.

    npmCompromised package
  1373. containedcritical

    Malware in type-plint

    Malware was discovered in the npm package type-plint, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a clean system.

    npmCompromised package
  1374. resolvedcritical

    Malware in type-elint

    The npm package type-elint contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1375. containedcritical

    Malware in type-atob

    Malware was discovered in the npm package type-atob. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1376. containedcritical

    Malware in @redhat-cloud-services/frontend-components-notifications

    Malware was discovered in the npm package @redhat-cloud-services/frontend-components-notifications. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1377. containedcritical

    Malware in polygon-gamma-apis

    Malware was discovered in the npm package polygon-gamma-apis. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1378. containedcritical

    Malware in @redhat-cloud-services/javascript-clients-shared

    Malware was discovered in the npm package @redhat-cloud-services/javascript-clients-shared. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1379. containedcritical

    Malware in @redhat-cloud-services/notifications-client

    Malware was discovered in the npm package @redhat-cloud-services/notifications-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1380. resolvedcritical

    Malware in @redhat-cloud-services/patch-client

    Malware was discovered in the npm package @redhat-cloud-services/patch-client. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1381. containedcritical

    Malware in @redhat-cloud-services/hcc-pf-mcp

    Malware was discovered in the npm package @redhat-cloud-services/hcc-pf-mcp. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1382. activecritical

    Malware in eslint-jest

    Malware discovered in the eslint-jest npm package. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1383. activecritical

    Malware in @redhat-cloud-services/host-inventory-client

    Malware was discovered in the npm package @redhat-cloud-services/host-inventory-client. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1384. activecritical

    Malware in nodemon-gulp

    Malware discovered in the npm package nodemon-gulp. Any system with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1385. activecritical

    Malware in nodepack-daemon

    Malware was discovered in the npm package nodepack-daemon. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1386. containedcritical

    Malware in @redhat-cloud-services/config-manager-client

    Malware was discovered in the npm package @redhat-cloud-services/config-manager-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1387. containedcritical

    Malware in @redhat-cloud-services/frontend-components-advisor-components

    Malware was discovered in the npm package @redhat-cloud-services/frontend-components-advisor-components. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1388. containedcritical

    Malware in @redhat-cloud-services/hcc-kessel-mcp

    Malware was discovered in the npm package @redhat-cloud-services/hcc-kessel-mcp. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1389. containedcritical

    Malware in @redhat-cloud-services/insights-client

    Malware was discovered in the npm package @redhat-cloud-services/insights-client. Systems with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different computer.

    npmCompromised package
  1390. containedcritical

    Malware in @redhat-cloud-services/remediations-client

    Malware was discovered in the npm package @redhat-cloud-services/remediations-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1391. containedcritical

    Malware in @redhat-cloud-services/tsc-transform-imports

    Malware was discovered in the npm package @redhat-cloud-services/tsc-transform-imports. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1392. activecritical

    Malware in ts-eslint-jest

    Malware discovered in the npm package ts-eslint-jest. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1393. containedcritical

    Malware in @redhat-cloud-services/frontend-components-notifications

    Malware was discovered in the npm package @redhat-cloud-services/frontend-components-notifications. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1394. activecritical

    Malware in marked-prettier

    Malware was discovered in the npm package marked-prettier. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1395. containedcritical

    Malware in polymarket-gamma-apis

    Malware was discovered in the npm package polymarket-gamma-apis. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1396. containedcritical

    Malware in polygon-gama-apis

    The npm package polygon-gama-apis was found to contain malware, potentially providing full system compromise to attackers. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  1397. activecritical

    Malware in polymarket-apis

    Malware was discovered in the npm package polymarket-apis. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1398. containedcritical

    Malware in polymarket-trader-apis

    Malware was discovered in the npm package polymarket-trader-apis. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1399. activecritical

    Malware in mdb-vite

    Malware was discovered in the npm package mdb-vite. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1400. containedcritical

    Malware in base62-86x

    The npm package base62-86x contained malware that could fully compromise any system where it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1401. activecritical

    Malware in oem-agentic-shared

    The npm package oem-agentic-shared contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmAI agents & skillsCompromised package
  1402. containedcritical

    Malware in page-info-service

    Malware was discovered in the npm package page-info-service, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a different computer.

    npmCompromised package
  1403. containedcritical

    Malware in po-ops-local-dev

    The npm package po-ops-local-dev was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-r7j7-4gwg-rg72 was published on 2026-07-10.

    npmCompromised package
  1404. containedcritical

    Malware in housecall-ui

    Malware was discovered in the npm package housecall-ui, affecting any computer with the package installed or running. The compromise is considered critical as it may grant full control of affected systems to an outside entity.

    npmCompromised package
  1405. containedcritical

    Malware in mazemap

    The npm package mazemap was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.

    npmCompromised package
  1406. containedcritical

    Malware in firefly-utilities-helper

    Malware was discovered in the npm package firefly-utilities-helper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1407. containedcritical

    Malware in ng-search-api

    Malware was discovered in the npm package ng-search-api. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1408. containedcritical

    Malware in motiondnb

    Malware was discovered in the npm package motiondnb, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1409. containedcritical

    Malware in ltidiconf

    The npm package ltidiconf was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1410. containedcritical

    Malware in visa-cli-tools

    The npm package visa-cli-tools was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1411. activecritical

    Malware in higherlogic-ocfe

    Malware discovered in the npm package higherlogic-ocfe. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1412. activecritical

    Malware in commons-ui-styles

    The npm package commons-ui-styles contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1413. containedcritical

    Malware in txs-builder-lib

    Malware was discovered in the npm package txs-builder-lib, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1414. containedcritical

    Malware in breeze-feature-flag-poc

    Malware was discovered in the npm package breeze-feature-flag-poc. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1415. activecritical

    Malware in feedback-api

    The npm package feedback-api contains malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  1416. resolvedcritical

    Malware in qlkube

    Malware was discovered in the npm package qlkube, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1417. activecritical

    Malware in rabi-snooze-api

    Malware discovered in the npm package rabi-snooze-api. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.

    npmCompromised package
  1418. activecritical

    Malware in mchain-sdk

    The npm package mchain-sdk contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1419. resolvedcritical

    Malware in nodemon-sudo

    The npm package nodemon-sudo contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1420. containedcritical

    Malware in clavue-agent-sdk

    Malware was discovered in the npm package clavue-agent-sdk, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1421. containedcritical

    Malware in myclaude-code

    Malware was discovered in the npm package myclaude-code. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1422. resolvedcritical

    Malware in calvuepro

    The npm package calvuepro contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1423. activecritical

    Malware in bizapi-portal

    The npm package bizapi-portal contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1424. resolvedcritical

    Malware in @kl-starfish/test-01

    Malware was distributed via the npm package @kl-starfish/test-01. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1425. containedcritical

    Malware in rio-design-tokens

    Malware was discovered in the npm package rio-design-tokens. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1426. resolvedcritical

    Malware in clavue

    The npm package clavue contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1427. containedcritical

    Malware in poc-node-npm

    Malware was discovered in the npm package poc-node-npm. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1428. containedcritical

    Malware in none123s

    The npm package none123s was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1429. activecritical

    Malware in @calm2026/imux

    The npm package @calm2026/imux contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1430. resolvedcritical

    Malware in clavuepro

    The npm package clavuepro contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1431. resolvedcritical

    Malware in fusion-client

    The npm package fusion-client contained malware that provided full system compromise to attackers. Any computer with the package installed should be considered fully compromised and all secrets and keys rotated from a different machine.

    npmCompromised package
  1432. containedcritical

    Malware in tslint-conf

    The npm package tslint-conf was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1433. activecritical

    Malware in gitlens

    Malware was discovered in the gitlens npm package. Systems with the package installed or running are considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1434. containedcritical

    Malware in security-console-ui

    Malware was discovered in the npm package security-console-ui. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1435. containedcritical

    Injective SDK on npm infected with cryptocurrency wallet stealer

    Hackers compromised the Injective Labs SDK GitHub repository and published a malicious npm package that stole cryptocurrency wallet private keys and mnemonic seed phrases from users who installed it.

    npmCompromised packageMalicious commit
  1436. activecritical

    Malware in n8n-nodes-mcputils

    Malware was discovered in the npm package n8n-nodes-mcputils. Systems with this package installed or running are considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1437. containedcritical

    Malware in airkey-mfa-react

    Malware was discovered in the npm package airkey-mfa-react. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1438. containedcritical

    Malware in chain-api-sdk

    Malware was discovered in the npm package chain-api-sdk. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1439. containedcritical

    Malware in tailwind-core

    Malware was distributed via the npm package tailwind-core. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1440. containedcritical

    Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Keys

    On July 8, 2026, attackers gained access to a trusted developer's npm account and injected backdoored code into 18 packages of the Injective blockchain SDK. The malicious code, disguised as analytics, stole wallet recovery phrases and private keys, exfiltrating them to an attacker-controlled server. The compromise was detected and remediated within an hour.

    npmAccount takeoverCompromised package
  1441. activecritical

    Malware in @vite-ln/build-ts

    The npm package @vite-ln/build-ts contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1442. containedcritical

    Malware in na-rony

    The npm package na-rony was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1443. resolvedcritical

    Malware in rony-testing

    The npm package rony-testing contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1444. containedcritical

    Malware in vite-json-pwa

    Malware was discovered in the npm package vite-json-pwa. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1445. activecritical

    Malware in ams-ssk

    The npm package ams-ssk contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1446. containedcritical

    Malware in karem-dp

    The npm package karem-dp was found to contain malware. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1447. containedcritical

    Malware in promo-helper

    The npm package promo-helper contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different machine.

    npmCompromised package
  1448. activecritical

    Malware in ts-await

    Malware discovered in the npm package ts-await. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1449. containedcritical

    Malware in common-tg-service

    The npm package common-tg-service was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1450. containedcritical

    Malware in nam-os-a-man

    The npm package nam-os-a-man contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1451. containedcritical

    Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials

    Malicious packages impersonating Paysafe, Skrill, and Neteller SDKs were published on npm and PyPI, delivering stealer malware designed to harvest credentials from developers and application users.

    npmPyPITyposquattingCompromised package
  1452. activecritical

    Malware in nodemon-node

    The npm package nodemon-node contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1453. resolvedcritical

    Malware in gas-log

    The npm package gas-log contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package
  1454. activecritical

    Malware in na-rony-test-karem

    The npm package na-rony-test-karem contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1455. resolvedcritical

    Malware in na-rony-test

    The npm package na-rony-test contained malware that could fully compromise any system on which it was installed or running. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  1456. activecritical

    Malware in mci-sdk

    Malware discovered in the npm package mci-sdk. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1457. activecritical

    Malware in @engagehub/test-claim

    Malware discovered in the npm package @engagehub/test-claim. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1458. containedcritical

    Malware in ai-sdk-helpers

    The npm package ai-sdk-helpers was found to contain malware, potentially providing full system compromise to attackers. All affected systems should be considered fully compromised and all credentials rotated immediately from a clean machine.

    npmAI agents & skillsCompromised package
  1459. containedcritical

    Malware in runtimedev-link

    Malware was discovered in the npm package runtimedev-link. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1460. containedcritical

    Malware in syco1

    Malware was discovered in the npm package syco1, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1461. activecritical

    Malware in express-deflect

    Malware discovered in the npm package express-deflect. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1462. activecritical

    Malware in @sqlite-list/sql-creator

    Malware discovered in the npm package @sqlite-list/sql-creator. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1463. containedcritical

    Malware in sypoi1

    The npm package sypoi1 contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1464. containedcritical

    Malware in wsh4-nmp

    The npm package wsh4-nmp was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1465. containedcritical

    Malware in @engagehub/core

    Malware was discovered in the npm package @engagehub/core. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1466. containedcritical

    Malware in whs4_npm_test

    The npm package whs4_npm_test contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1467. activecritical

    Malware in typescript-base58

    Malware was discovered in the npm package typescript-base58. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1468. activecritical

    Malware in @sqlite-list/createsql

    Malware discovered in the npm package @sqlite-list/createsql. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1469. containedcritical

    Malware in @aspect-security/argon2

    Malware was discovered in the npm package @aspect-security/argon2. Systems with this package installed or running should be considered fully compromised. All secrets and keys stored on affected computers should be rotated immediately from a different computer.

    npmCompromised package
  1470. containedcritical

    Malware in ollama-helpers

    The npm package ollama-helpers was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-73pg-hv45-6r54 was published on 2026-07-07.

    npmCompromised package
  1471. containedcritical

    Malware in chai-sdk

    Malware was discovered in the chai-sdk npm package. Systems with the package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1472. activecritical

    Malware in crypto-base58

    The npm package crypto-base58 was compromised and contains malware. Systems with this package installed are considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1473. activecritical

    Malware in rnx-align-deps

    Malware discovered in the npm package rnx-align-deps. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1474. activecritical

    Malware in @apexcraft/nano-key

    Malware was discovered in the npm package @apexcraft/nano-key. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1475. containedcritical

    Malware in chai-spycore

    Malware was discovered in the npm package chai-spycore, affecting any computer with the package installed or running. The compromise is considered critical as it grants full system control to an outside entity.

    npmCompromised package
  1476. containedcritical

    Malware in load-nuxt

    The npm package load-nuxt was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1477. containedcritical

    Malware in polytrade

    The npm package polytrade was found to contain malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1478. containedcritical

    Malware in chai-chain-dom

    Malware was discovered in the npm package chai-chain-dom. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.

    npmCompromised package
  1479. activecritical

    Malware in zod-pino434

    The npm package zod-pino434 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1480. resolvedcritical

    Malware in vps-maintenance

    The npm package vps-maintenance contained malware that provided full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1481. containedcritical

    Malware in base58-cli

    The npm package base58-cli was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1482. containedcritical

    Malware in gen-ai-opt-in

    The npm package gen-ai-opt-in was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-jwrj-q2c7-8g47 was published on 2026-07-07.

    npmCompromised package
  1483. activecritical

    Malware in paperclip2

    Malware was discovered in the npm package paperclip2. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1484. activecritical

    Malware in vps-adapter-core

    Malware discovered in the npm package vps-adapter-core. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1485. activecritical

    Malware in warp-dependency

    The npm package warp-dependency contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1486. containedcritical

    Malware in @43uh3ig43/telemetry-client

    Malware was discovered in the npm package @43uh3ig43/telemetry-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1487. activecritical

    Malware in hello244a

    The npm package hello244a contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1488. containedcritical

    Malware in wsh4_npm

    The npm package wsh4_npm contained malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1489. containedcritical

    Malware in zredis-typed

    The npm package zredis-typed was found to contain malware. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1490. activecritical

    Malware in vps-maintenance-paperclip-adapter

    Malware discovered in the npm package vps-maintenance-paperclip-adapter. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1491. activecritical

    Malware in whs4_pnm

    The npm package whs4_pnm contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1492. containedcritical

    Malware in @sqlite-list/schema-generator

    Malware was discovered in the npm package @sqlite-list/schema-generator. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1493. activecritical

    Malware in whs4_npm

    Malware discovered in the npm package whs4_npm. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1494. activecritical

    Malware in notifier-utils

    Malware discovered in the npm package notifier-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1495. containedcritical

    Malware in base58-core

    Malware was discovered in the npm package base58-core. Systems with the package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1496. containedcritical

    Malware in openai-agents-helpers

    The npm package openai-agents-helpers was found to contain malware. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmAI agents & skillsCompromised package
  1497. activecritical

    Malware in @whs4/whs4_npm

    Malware discovered in the npm package @whs4/whs4_npm. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1498. activecritical

    Malware in jsf-utils

    The npm package jsf-utils contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  1499. activecritical

    Malware in paperclip-host-utils

    Malware discovered in the npm package paperclip-host-utils. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1500. activecritical

    Malware in express-firegate

    Malware discovered in the npm package express-firegate. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1501. resolvedcritical

    Malware in harmony-enablers-test-2026

    Malware was discovered in the npm package harmony-enablers-test-2026. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.

    npmCompromised package
  1502. containedcritical

    Malware in solana-address-codec

    Malware was discovered in the npm package solana-address-codec. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1503. containedcritical

    Malware in brunomenozzi-test-pkg

    Malware was discovered in the npm package brunomenozzi-test-pkg. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1504. containedcritical

    Malware in anthropic-toolkit

    Malware was discovered in the npm package anthropic-toolkit. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1505. activecritical

    Malware in mcp-server-pg

    Malware discovered in the npm package mcp-server-pg. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1506. containedcritical

    Malware in debugcli

    The npm package debugcli was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-86fh-6m37-f9v4 was published on 2026-07-07.

    npmCompromised package
  1507. activecritical

    Malware in some-theme

    Malware discovered in the npm package some-theme. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1508. containedcritical

    Malware in @langgraphjs/toolkit

    Malware was discovered in the npm package @langgraphjs/toolkit. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1509. activecritical

    Malware in whs4_nmp

    The npm package whs4_nmp contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1510. containedcritical

    Malware in hook-augmenting-module

    Malware was discovered in the npm package hook-augmenting-module, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.

    npmCompromised package
  1511. containedcritical

    Malware in tx-guard-snap

    Malware was discovered in the npm package tx-guard-snap. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1512. activecritical

    Malware in nonexistent-package

    Malware discovered in the npm package nonexistent-package. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1513. activecritical

    Malware in annotator-harvardx

    The npm package annotator-harvardx contains malware that provides full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1514. containedcritical

    Malware in shopify-internel

    The npm package shopify-internel was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1515. activecritical

    Malware in load-nuxt-dev

    The npm package load-nuxt-dev was found to contain malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1516. containedcritical

    Malware in tailwindcss-effector

    Malware was discovered in the npm package tailwindcss-effector. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1517. activecritical

    Malware in tailwind-animator-scroll

    The npm package tailwind-animator-scroll contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1518. containedcritical

    Malware in nuxt-fonts-devtools

    Malware was discovered in the npm package nuxt-fonts-devtools. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1519. containedcritical

    Malware in evm-typechain

    Malware was discovered in the npm package evm-typechain. Systems with this package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1520. activecritical

    Malware in zod-pino444

    The npm package zod-pino444 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1521. activecritical

    Malware in pinokio-redis

    Malware discovered in the npm package pinokio-redis. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1522. activecritical

    Malware in @sqlite-access/nodesql

    Malware discovered in the npm package @sqlite-access/nodesql. Systems with this package installed are considered fully compromised and may have given outside entities full control of the computer.

    npmCompromised package
  1523. activecritical

    Malware in react-check-error

    The npm package react-check-error contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1524. activecritical

    Malware in npm-doc-dev

    The npm package npm-doc-dev contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets/keys rotated immediately from a different machine.

    npmCompromised package
  1525. activecritical

    Malware in ether-bn.js

    Malware discovered in the ether-bn.js npm package. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1526. activecritical

    Malware in lint-builds

    The npm package lint-builds contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1527. activecritical

    Malware in pino-formatter

    Malware discovered in the npm package pino-formatter. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1528. containedcritical

    Malware in picocolor-logger

    Malware was discovered in the npm package picocolor-logger. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1529. containedcritical

    Malware in pino-utils

    The npm package pino-utils was compromised and distributed with malware. Any system with the package installed should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1530. activecritical

    Malware in pino-sdk-v2

    Malware discovered in the npm package pino-sdk-v2. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1531. activecritical

    Malware in pino-pretty-logs

    The npm package pino-pretty-logs was found to contain malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1532. containedcritical

    Malware in metrica-chain

    The npm package metrica-chain was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1533. activecritical

    Malware in chai-guard

    Malware discovered in the npm package chai-guard. Any computer with this package installed or running should be considered fully compromised. All secrets and keys stored on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1534. containedcritical

    Malware in log-upgrade

    The npm package log-upgrade contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1535. containedcritical

    Malware in mjs-biginteger

    Malware was discovered in the npm package mjs-biginteger. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1536. containedcritical

    Malware in hjs-biginteger

    Malware was discovered in the npm package hjs-biginteger, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1537. containedcritical

    Malware in logger-beauty

    Malware was discovered in the npm package logger-beauty. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.

    npmCompromised package
  1538. activecritical

    Malware in js-unimode

    The npm package js-unimode contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1539. containedcritical

    Malware in jsontoken-extend

    Malware was discovered in the npm package jsontoken-extend. Systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1540. containedcritical

    Malware in modulyn

    The npm package modulyn was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1541. containedcritical

    Malware in linter-entry

    The npm package linter-entry contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1542. containedcritical

    Malware in lint-null

    The npm package lint-null was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1543. activecritical

    Malware in color-logger-console

    The npm package color-logger-console contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1544. containedcritical

    Malware in next-bignumber.js

    Malware was discovered in the npm package next-bignumber.js. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1545. containedcritical

    Malware in debug-glitzs

    Malware was discovered in the npm package debug-glitzs. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1546. containedcritical

    Malware in df-vision

    The npm package df-vision contained malware that could fully compromise any system on which it was installed. GitHub Security Advisory GHSA-wvvx-jr39-8g7j documents the incident as critical severity.

    npmCompromised package
  1547. containedcritical

    Malware in node-env-detector

    The npm package node-env-detector was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1548. containedcritical

    Malware in npm-eslint-helper

    Malware was discovered in the npm package npm-eslint-helper. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1549. activecritical

    Malware in older_morgan

    The npm package older_morgan contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1550. activecritical

    Malware in peptideenv

    The npm package peptideenv contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1551. activecritical

    Malware in nodepathbalance54

    The npm package nodepathbalance54 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1552. activecritical

    Malware in polymarket-onchain-plugin

    Malware was discovered in the polymarket-onchain-plugin npm package. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1553. activecritical

    Malware in prettier-logger

    The npm package prettier-logger contains malware that grants full control of affected systems. All systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1554. activecritical

    Malware in pretty-pino-loggers

    Malware was discovered in the npm package pretty-pino-loggers. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate computer.

    npmCompromised package
  1555. activecritical

    Malware in random-string-64

    The npm package random-string-64 contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1556. activecritical

    Malware in pretty-pino-logger

    Malware was discovered in the npm package pretty-pino-logger. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1557. activecritical

    Malware in request-js-validator

    Malware discovered in the npm package request-js-validator. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1558. containedcritical

    Malware in router-kit

    Malware was discovered in the npm package router-kit, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.

    npmCompromised package
  1559. containedcritical

    Malware in sjs-builders

    The npm package sjs-builders was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1560. activecritical

    Malware in set-proto-chain

    Malware discovered in the npm package set-proto-chain. The package is confirmed to contain malicious code that grants full system compromise to attackers. All systems with this package installed should be considered fully compromised.

    npmCompromised package
  1561. activecritical

    Malware in st-bigintr

    The npm package st-bigintr contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1562. containedcritical

    Malware in secure-box

    The npm package secure-box was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1563. activecritical

    Malware in tailwind-scroller

    Malware discovered in the npm package tailwind-scroller. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1564. containedcritical

    Malware in styled-text-logger

    The npm package styled-text-logger contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1565. containedcritical

    Malware in sjs-biginteger

    Malware was discovered in the npm package sjs-biginteger. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1566. activecritical

    Malware in subsearch

    The npm package subsearch contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1567. containedcritical

    Malware in tailstyle-core

    Malware was discovered in the npm package tailstyle-core. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1568. resolvedcritical

    Malware in sleek-pretty

    The npm package sleek-pretty was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1569. activecritical

    Malware in st-biginteger

    Malware discovered in the npm package st-biginteger. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1570. containedcritical

    Malware in sol-sdk

    Malware was discovered in the sol-sdk npm package. Any computer with the package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1571. containedcritical

    Malware in stacknova

    The npm package stacknova was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1572. activecritical

    Malware in tailwindcss-framer-motion

    Malware was discovered in the npm package tailwindcss-framer-motion. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1573. activecritical

    Malware in tailwindcss-svg-helper

    Malware was discovered in the npm package tailwindcss-svg-helper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1574. containedcritical

    Malware in tailwindcss-fonttype-inter

    The npm package tailwindcss-fonttype-inter contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1575. containedcritical

    Malware in theta-kit

    Malware was discovered in the npm package theta-kit, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1576. resolvedcritical

    Malware in test-prettier

    The npm package test-prettier contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1577. activecritical

    Malware in color-cli-log

    The npm package color-cli-log contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1578. containedcritical

    Malware in tracing-str

    The npm package tracing-str was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1579. activecritical

    Malware in tailwind-typography-plus

    The npm package tailwind-typography-plus contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1580. containedcritical

    Malware in ts-bigtn

    The npm package ts-bigtn was found to contain malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1581. containedcritical

    Malware in theta-connector

    Malware was discovered in the npm package theta-connector, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1582. resolvedcritical

    Malware in competion

    The npm package 'competion' contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1583. activecritical

    Malware in ts-relayer-pub

    Malware was discovered in the npm package ts-relayer-pub. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1584. activecritical

    Malware in ts-build-optimize

    Malware discovered in the npm package ts-build-optimize. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1585. containedcritical

    Malware in rma-utils

    Malware was discovered in the npm package rma-utils, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.

    npmCompromised package
  1586. containedcritical

    Malware in ts-lint-builds

    The npm package ts-lint-builds contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1587. containedcritical

    Malware in ts-eslinter

    Malware was discovered in the ts-eslinter npm package. Systems with the package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer, and the package should be removed.

    npmCompromised package
  1588. resolvedcritical

    Malware in tsliverhome

    The npm package tsliverhome contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1589. containedcritical

    Malware in ts-lint-builders

    Malware was discovered in the npm package ts-lint-builders. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1590. activecritical

    Malware in renderctx

    Malware was discovered in the npm package renderctx. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1591. activecritical

    Malware in txs-data

    The npm package txs-data contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1592. activecritical

    Malware in twcompose-utils

    The npm package twcompose-utils contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1593. activecritical

    Malware in tailwindcss-fonttypo-inter

    Malware discovered in the npm package tailwindcss-fonttypo-inter. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1594. containedcritical

    Malware in windrule-utils

    Malware was discovered in the npm package windrule-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1595. containedcritical

    Malware in tailwindcss-animatecss-latest

    The npm package tailwindcss-animatecss-latest contained malware that provided full system compromise to attackers. Systems with this package installed should be considered fully compromised and all credentials rotated immediately.

    npmCompromised package
  1596. activecritical

    Malware in vite-plugin-compress-js

    Malware discovered in the npm package vite-plugin-compress-js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1597. activecritical

    Malware in webpack-cache-clean

    The npm package webpack-cache-clean contains malware that grants full system compromise to an attacker. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1598. containedcritical

    Malware in unique-id-64

    The npm package unique-id-64 was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1599. activecritical

    Malware in normalize-path-seq

    Malware discovered in the npm package normalize-path-seq. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.

    npmCompromised package
  1600. containedcritical

    Malware in web-pool

    The npm package web-pool was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1601. activecritical

    Malware in wime-zle

    The npm package wime-zle contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1602. activecritical

    Malware in vite-plugin-svg-paths

    The npm package vite-plugin-svg-paths was compromised and distributed with malware. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  1603. activecritical

    Malware in winston-js-express

    The npm package winston-js-express contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1604. activecritical

    Malware in winston-prism

    Malware discovered in the npm package winston-prism. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1605. activecritical

    Malware in xnder-sdk-js

    Malware discovered in the npm package xnder-sdk-js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1606. resolvedcritical

    Malware in @jaime9008/math-service

    The npm package @jaime9008/math-service contained malware that could fully compromise any system on which it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1607. containedcritical

    Malware in lint-builders

    The npm package lint-builders contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1608. activecritical

    Malware in log-format-thread

    The npm package log-format-thread contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1609. containedcritical

    Malware in metrica-node

    The npm package metrica-node was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1610. containedcritical

    Malware in chalk-pro-logger

    The npm package chalk-pro-logger was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1611. activecritical

    Malware in chalki-pretty

    Malware discovered in the npm package chalki-pretty. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1612. containedcritical

    Malware in polymarket-onchain-sdk

    Malware was discovered in the polymarket-onchain-sdk npm package. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1613. activecritical

    Malware in mongoose-json-format

    Malware discovered in the npm package mongoose-json-format. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1614. containedcritical

    Malware in typedecode

    Malware was discovered in the npm package typedecode. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1615. containedcritical

    Malware in tailwind-fonttype-inter

    Malware was discovered in the npm package tailwind-fonttype-inter. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1616. containedcritical

    Malware in syncora

    The npm package syncora was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1617. activecritical

    Malware in sjs-lint-build1

    Malware discovered in the npm package sjs-lint-build1. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.

    npmCompromised package
  1618. containedcritical

    Malware in motion-lib

    The npm package motion-lib was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1619. containedcritical

    Malware in sjs-builder

    The npm package sjs-builder contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets rotated from a different machine.

    npmCompromised package
  1620. containedcritical

    Malware in safe-validate

    The npm package safe-validate was compromised and distributed with malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1621. activecritical

    Malware in react-svg-render

    Malware discovered in the npm package react-svg-render. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1622. resolvedcritical

    Malware in react-native-template-my-starter

    Malware was discovered in the npm package react-native-template-my-starter. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1623. containedcritical

    Malware in typescript-util-core

    The npm package typescript-util-core was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1624. activecritical

    Malware in @sql-trigger/nodesql

    Malware discovered in the npm package @sql-trigger/nodesql. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1625. activecritical

    Malware in @sql-access/nodesql

    Malware discovered in the npm package @sql-access/nodesql. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1626. containedcritical

    Malware in alder_morrgan

    The npm package alder_morrgan was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1627. containedcritical

    Malware in ts-node-utils

    The npm package ts-node-utils was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-mjvg-2r5j-mg76 was published on 2026-07-03.

    npmCompromised package
  1628. containedcritical

    Malware in @jacobtan/decode-sdk

    The npm package @jacobtan/decode-sdk contained malware that could fully compromise any system where it was installed or executed. Systems with this package should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  1629. containedcritical

    Malware in api-ts-utils

    Malware was discovered in the npm package api-ts-utils. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1630. containedcritical

    Malware in web-api-node

    Malware was discovered in the npm package web-api-node. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1631. containedcritical

    Malware in @lodash-en/lodash-en

    Malware was discovered in the npm package @lodash-en/lodash-en. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1632. activecritical

    Malware in decode-sdks

    The npm package decode-sdks contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1633. activecritical

    Malware in @sqlite-node/createsql

    Malware was discovered in the npm package @sqlite-node/createsql. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1634. containedcritical

    Malware in @node-cloud/create

    Malware was discovered in the npm package @node-cloud/create. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1635. resolvedcritical

    Malware in @antoncarlos1/nodelamp

    Malware was distributed via the npm package @antoncarlos1/nodelamp, resulting in full system compromise of affected installations. The package has been identified and removed from distribution.

    npmCompromised package
  1636. containedcritical

    Malware in api-node-utils

    Malware was discovered in the npm package api-node-utils. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1637. activecritical

    Malware in tailwind-typography-stylecss

    Malware discovered in the npm package tailwind-typography-stylecss. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1638. activecritical

    Malware in db-connector-log

    Malware discovered in the npm package db-connector-log. Systems with this package installed or running should be considered fully compromised.

    npmCompromised package
  1639. activecritical

    Malware in db-convertor

    Malware discovered in the npm package db-convertor. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1640. resolvedcritical

    Malware in @modhamanish/rn-mm-template

    The npm package @modhamanish/rn-mm-template contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1641. activecritical

    Malware in animatecss-postcss-plugin

    Malware discovered in the npm package animatecss-postcss-plugin. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1642. containedcritical

    Malware in tailwind-animates

    Malware was discovered in the npm package tailwind-animates. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1643. activecritical

    Malware in vitest-agent

    Malware was discovered in the npm package vitest-agent. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1644. containedcritical

    Malware in db-plog

    Malware was discovered in the npm package db-plog, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1645. containedcritical

    Malware in cache-section-helper

    Malware was discovered in the npm package cache-section-helper. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1646. activehigh

    New ChocoPoC malware targets researchers via trojanized PoC exploits

    Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering ChocoPoC, a Python-based remote access trojan (RAT) capable of executing commands and stealing sensitive data. The campaign is believed to target cybersecurity researchers.

    OtherMalicious commitCompromised package
  1647. activecritical

    Malware in chai-as-persisted

    Malware was discovered in the npm package chai-as-persisted. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1648. containedcritical

    Malware in terminal-prettier

    Malware was discovered in the npm package terminal-prettier. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1649. containedcritical

    Malware in ts-linting-builder

    The npm package ts-linting-builder contained malware that could fully compromise affected systems. All systems with this package installed should be considered compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  1650. activecritical

    Malware in livekit-agents

    Malware was discovered in the livekit-agents npm package. Systems with the package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1651. containedcritical

    Malware in setup-cicd

    The npm package setup-cicd was found to contain malware, potentially giving outside entities full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmOtherCompromised package
  1652. containedcritical

    Malware in confluent-kafka-javascript

    Malware was discovered in the confluent-kafka-javascript npm package. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1653. containedcritical

    Malware in nbmolviz-js

    Malware was discovered in the npm package nbmolviz-js. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1654. containedcritical

    Malware in awaitly-analyze

    The npm package awaitly-analyze was found to contain malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all credentials rotated immediately from a different machine.

    npmCompromised package
  1655. containedcritical

    Malware in chai-as-assured

    Malware was discovered in the npm package chai-as-assured. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1656. containedcritical

    Malware in rs-biginteger

    Malware was discovered in the npm package rs-biginteger, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1657. resolvedcritical

    Malware in ts-lint-builders-v2.1

    The npm package ts-lint-builders-v2.1 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1658. activecritical

    Malware in rebrandly-domains-search-client

    Malware discovered in the npm package rebrandly-domains-search-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1659. containedcritical

    Malware in brock-loader

    Malware was discovered in the npm package brock-loader, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1660. containedcritical

    Malware in agent-starter-pack

    Malware was discovered in the npm package agent-starter-pack. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1661. containedcritical

    Malware in postcss-property-rollup

    Malware was discovered in the npm package postcss-property-rollup. The package is considered to provide full system compromise to any computer where it is installed or running.

    npmCompromised package
  1662. containedcritical

    Malware in quoting

    The npm package 'quoting' was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-x8q6-66jr-wmp3 was published on 2026-06-30.

    npmCompromised package
  1663. activecritical

    Malware in brock-react-alerts

    Malware discovered in the npm package brock-react-alerts. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.

    npmCompromised package
  1664. containedcritical

    Malware in autotel-mcp-instrumentation

    Malware was discovered in the npm package autotel-mcp-instrumentation. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1665. containedcritical

    Malware in procwire

    Malware was discovered in the npm package procwire, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1666. containedcritical

    Malware in awaitly-mongo

    The npm package awaitly-mongo was found to contain malware, resulting in full system compromise for any computer with the package installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1667. activecritical

    Malware in ai-sdk-ollama

    Malware discovered in the ai-sdk-ollama npm package. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  1668. activecritical

    Malware in autotel-drizzle

    Malware discovered in the npm package autotel-drizzle. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1669. containedcritical

    Malware in autotel-sentry

    Malware was discovered in the npm package autotel-sentry, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1670. containedcritical

    Malware in autotel-plugins

    The npm package autotel-plugins was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1671. activecritical

    Malware in autotel-mongoose

    Malware was discovered in the npm package autotel-mongoose. Systems with this package installed or running should be considered fully compromised.

    npmCompromised package
  1672. containedcritical

    Malware in autotel-tanstack

    Malware was discovered in the npm package autotel-tanstack. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1673. containedcritical

    Malware in autotel-vitest

    Malware was discovered in the npm package autotel-vitest. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1674. containedcritical

    Malware in autotel-web

    The npm package autotel-web was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1675. resolvedcritical

    Malware in endpointmap

    The npm package endpointmap contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1676. containedcritical

    Malware in rebrandly-domains-digger

    Malware was discovered in the npm package rebrandly-domains-digger, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1677. activecritical

    Malware in autotel-mcp

    The npm package autotel-mcp contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1678. activecritical

    Malware in autotel-eventcatalog

    Malware was discovered in the npm package autotel-eventcatalog. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1679. containedcritical

    Malware in autotel-hono

    Malware was discovered in the npm package autotel-hono. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1680. activehigh

    Malicious PyPI packages give hackers control of Telegram bot servers

    A campaign active since November 2025 has distributed malicious PyPI packages—trojanized Pyrogram forks—targeting Python developers building Telegram bots. The compromised packages allow attackers to read arbitrary files on affected servers.

    PyPICompromised packageTyposquatting
  1681. containedcritical

    Malware in autotel-subscribers

    The npm package autotel-subscribers was found to contain malware that grants full system compromise to an outside entity. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1682. containedcritical

    Malware in autotel-playwright

    Malware was discovered in the npm package autotel-playwright. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1683. containedcritical

    Malware in awaitly-libsql

    The npm package awaitly-libsql was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1684. resolvedcritical

    Malware in awaitly

    The npm package awaitly contained malware that provided full system compromise to attackers. Any system with the package installed should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  1685. activecritical

    Malware in autotel-pact

    The npm package autotel-pact contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1686. activecritical

    Malware in @oec-settlement/react-router

    Malware discovered in the npm package @oec-settlement/react-router. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1687. containedcritical

    Malware in @multformats/multiaddr

    Malware was discovered in the npm package @multformats/multiaddr. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1688. containedcritical

    Malware in @reference-web/pmp-i18n

    Malware was discovered in the npm package @reference-web/pmp-i18n. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1689. containedcritical

    Malware in @partner-apps/ui

    Malware was discovered in the npm package @partner-apps/ui. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1690. containedcritical

    Malware in @rakuten-rewards/messaging-sdk-js

    Malware was discovered in the npm package @rakuten-rewards/messaging-sdk-js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1691. activecritical

    Malware in @serasa/core

    Malware discovered in the npm package @serasa/core. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1692. containedcritical

    Malware in @rmlibrary/formatting

    Malware was discovered in the npm package @rmlibrary/formatting. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1693. activecritical

    Malware in @services-lib/application-http-client

    Malware discovered in the npm package @services-lib/application-http-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1694. activecritical

    Malware in @settle-sea/supporting-documents

    Malware discovered in the npm package @settle-sea/supporting-documents. Systems with this package installed are considered fully compromised with potential for complete system control by external entities.

    npmCompromised package
  1695. containedcritical

    Malware in gel-bootstrap

    Malware was discovered in the npm package gel-bootstrap. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1696. resolvedcritical

    Malware in autotel-cloudflare

    Malware was discovered in the npm package autotel-cloudflare, resulting in full system compromise of any computer with the package installed or running. The package has been flagged as critical and requires immediate removal and credential rotation.

    npmCompromised package
  1697. containedcritical

    Malware in @content-editor/common

    Malware was discovered in the npm package @content-editor/common. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1698. activecritical

    Malware in @contenteditor-shared/content-editor-common

    Malware discovered in the npm package @contenteditor-shared/content-editor-common. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1699. activecritical

    Malware in gx-npm-lib

    Malware discovered in the npm package gx-npm-lib. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1700. containedcritical

    Malware in @anna-money/anna-web-lib

    Malware was discovered in the npm package @anna-money/anna-web-lib. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1701. resolvedcritical

    Malware in @cxp-shared/string-utilities

    Malware was discovered in the npm package @cxp-shared/string-utilities. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1702. resolvedcritical

    Malware in @hg-aka-prml/tapas-common

    Malware was discovered in the npm package @hg-aka-prml/tapas-common, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1703. resolvedcritical

    Malware in @epsteinlovekids483/crossmint-wallets-sdk-pentest

    Malware was distributed via the npm package @epsteinlovekids483/crossmint-wallets-sdk-pentest. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1704. containedcritical

    Malware in gx-npm-feature-flags

    Malware was discovered in the npm package gx-npm-feature-flags. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1705. activecritical

    Malware in @fed-sofia/jetify

    Malware discovered in the npm package @fed-sofia/jetify. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1706. activecritical

    Malware in @img-hls/vtt.js

    Malware discovered in the npm package @img-hls/vtt.js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1707. activecritical

    Malware in @meego-progressive/cdk

    Malware discovered in the npm package @meego-progressive/cdk. Systems with this package installed are considered fully compromised with potential for complete system takeover.

    npmCompromised package
  1708. containedcritical

    Malware in ts-einkle-slot

    Malware was discovered in the npm package ts-einkle-slot. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1709. activecritical

    Malware in @ms-ows/logging

    Malware discovered in the npm package @ms-ows/logging. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1710. containedcritical

    Malware in @e50/utils

    The npm package @e50/utils was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  1711. activecritical

    Malware in @postman-app-monolith/renderer

    Malware was discovered in the npm package @postman-app-monolith/renderer. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1712. resolvedcritical

    Malware in velocityfix

    The npm package velocityfix contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1713. containedcritical

    Malware in @riskine-frontend/design-elements

    Malware was discovered in the npm package @riskine-frontend/design-elements. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1714. activecritical

    Malware in @report-portal/service-ui

    Malware was discovered in the npm package @report-portal/service-ui. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1715. activecritical

    Malware in ts-einkle

    Malware discovered in the npm package ts-einkle. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1716. containedcritical

    Malware in @vpms/design-system

    Malware was discovered in the npm package @vpms/design-system. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1717. containedcritical

    Malware in gx-npm-ui

    Malware was discovered in the npm package gx-npm-ui, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1718. resolvedcritical

    Malware in @piewasm/pie-web-npm-package

    Malware was discovered in the npm package @piewasm/pie-web-npm-package, providing full system compromise to any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a separate, uncompromised system.

    npmCompromised package
  1719. activecritical

    Malware in @sec-loans-ui/utils

    Malware discovered in the npm package @sec-loans-ui/utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1720. activecritical

    Malware in via-city-tools-m-particle

    The npm package via-city-tools-m-particle contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1721. activecritical

    Malware in sorenson-webfonts

    The npm package sorenson-webfonts contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1722. containedcritical

    Malware in ui-ng-components

    Malware was discovered in the npm package ui-ng-components. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1723. containedcritical

    Malware in polymarket-clob-math

    Malware was discovered in the npm package polymarket-clob-math. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1724. containedcritical

    Malware in @cseo-hr/trpweb-shared

    Malware was discovered in the npm package @cseo-hr/trpweb-shared. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1725. activecritical

    Malware in @bscom/styling

    The npm package @bscom/styling contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1726. containedcritical

    Malware in @citi-icg-171632/citicms-repo-component

    The npm package @citi-icg-171632/citicms-repo-component contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1727. activecritical

    Malware in unsafe-malicious-package

    Malware discovered in the npm package unsafe-malicious-package. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1728. containedcritical

    Malware in @webda-infra/search

    Malware was discovered in the npm package @webda-infra/search. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1729. activecritical

    Malware in @contentprod-authoring/block-manager

    Malware was discovered in the npm package @contentprod-authoring/block-manager. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1730. activecritical

    Malware in @sixt-payment/form-react

    Malware discovered in the npm package @sixt-payment/form-react. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1731. containedcritical

    Malware in @bodata/angular-client

    Malware was discovered in the npm package @bodata/angular-client. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1732. activecritical

    Malware in @deel-ui/animation

    The npm package @deel-ui/animation was found to contain malware. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1733. containedcritical

    Malware in @alerts/components

    Malware was distributed via the npm package @alerts/components. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1734. containedcritical

    Malware in unleash-js

    Malware was discovered in the unleash-js npm package. Systems with the package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1735. activecritical

    Malware in @digitalpharmacist/http-error-util

    Malware discovered in the npm package @digitalpharmacist/http-error-util. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1736. containedcritical

    Malware in ts-ankle

    The npm package ts-ankle was found to contain malware. Any system with the package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1737. containedcritical

    Malware in @deel-core/client-payroll-onboarding-types

    Malware was discovered in the npm package @deel-core/client-payroll-onboarding-types. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1738. containedcritical

    Malware in @webd-infra/query-designer-domain

    Malware was discovered in the npm package @webd-infra/query-designer-domain. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1739. activecritical

    Malware in tivo-codelib-a

    Malware discovered in the npm package tivo-codelib-a. Installation results in full system compromise with potential for complete attacker control.

    npmCompromised package
  1740. containedcritical

    Malware in path-internal-util

    The npm package path-internal-util was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  1741. containedcritical

    Malware in @postidigital-feature/oneaccount-orgadmin-front

    Malware was discovered in the npm package @postidigital-feature/oneaccount-orgadmin-front. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1742. activecritical

    Malware in authsessionbridge

    The npm package authsessionbridge contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1743. resolvedcritical

    Malware in vkzmn

    The npm package vkzmn contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1744. containedcritical

    Malware in auth-state-service

    Malware was discovered in the npm package auth-state-service. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1745. containedcritical

    Malware in ssr-auth-sync

    Malware was discovered in the npm package ssr-auth-sync. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1746. containedcritical

    Malware in test-nonmal-pkg-5

    Malware was discovered in the npm package test-nonmal-pkg-5. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  1747. containedcritical

    Malware in pvd3

    Malware was discovered in the npm package pvd3. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1748. activecritical

    Malware in rc-icon

    Malware discovered in the npm package rc-icon. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1749. containedcritical

    Malware in react-resource-router-next

    Malware was discovered in the npm package react-resource-router-next. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation.

    npmCompromised package
  1750. containedcritical

    Malware in eslint-plugin-totara

    Malware was discovered in the npm package eslint-plugin-totara. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1751. containedcritical

    Malware in cdocs-markdoc

    Malware was discovered in the npm package cdocs-markdoc. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.

    npmCompromised package
  1752. resolvedcritical

    Malware in @mcconnect/mcc-common-lib

    Malware was discovered in the npm package @mcconnect/mcc-common-lib. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1753. activecritical

    Malware in @grappi/automations

    Malware discovered in the npm package @grappi/automations. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1754. activecritical

    Malware in @sumoinc/trashpanda

    The npm package @sumoinc/trashpanda contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1755. activecritical

    Malware in @huobi-ui/activity-components

    Malware was discovered in the npm package @huobi-ui/activity-components. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1756. containedcritical

    Malware in @gallup/pc-utils

    The npm package @gallup/pc-utils contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1757. containedcritical

    Malware in authmatrix

    Malware was discovered in the npm package authmatrix, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1758. activecritical

    Malware in alpine-csp

    The npm package alpine-csp contains malware that grants full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1759. activecritical

    Malware in @live-backstage-im/communication-chat

    Malware discovered in the npm package @live-backstage-im/communication-chat. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1760. containedcritical

    Malware in @finantix/webcomponents

    Malware was discovered in the npm package @finantix/webcomponents. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1761. containedcritical

    Malware in @rakuten-rewards/messaging-sdk

    Malware was discovered in the npm package @rakuten-rewards/messaging-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1762. containedcritical

    Malware in @sentryx-libraries/auth-interceptor

    Malware was discovered in the npm package @sentryx-libraries/auth-interceptor. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1763. activecritical

    Malware in autotel-devtools

    Malware was discovered in the npm package autotel-devtools. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1764. activecritical

    Malware in @druidsoft/botframework-directlinejs

    Malware was discovered in the npm package @druidsoft/botframework-directlinejs. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1765. activecritical

    Malware in @ddh-libs/analytics

    Malware discovered in the npm package @ddh-libs/analytics. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1766. containedcritical

    Malware in @mc-xp/mc-monolith-js-src-package

    The npm package @mc-xp/mc-monolith-js-src-package contained malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1767. activecritical

    Malware in @orbis-lr-sdk/orbis-lr-sdk

    Malware was discovered in the npm package @orbis-lr-sdk/orbis-lr-sdk. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1768. activecritical

    Malware in @tbe-ui/ides

    Malware discovered in the npm package @tbe-ui/ides. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1769. containedcritical

    Malware in @react-thee/rapier

    Malware was discovered in the npm package @react-thee/rapier. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1770. activecritical

    Malware in @planetlabs/admin-ng

    Malware was discovered in the npm package @planetlabs/admin-ng. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1771. activecritical

    Malware in wm-mapper

    The npm package wm-mapper contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1772. activecritical

    Malware in uipath-sugar-sell

    Malware discovered in the npm package uipath-sugar-sell. Systems with this package installed are considered fully compromised and may have given outside entities full control.

    npmCompromised package
  1773. activecritical

    Malware in @appsource/utils

    The npm package @appsource/utils contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1774. activecritical

    Malware in @concerns/i18n

    Malware discovered in the npm package @concerns/i18n. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1775. activecritical

    Malware in @webda-features/dashboard

    Malware discovered in the npm package @webda-features/dashboard. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1776. activecritical

    Malware in @bc-workspace/utils

    Malware discovered in the npm package @bc-workspace/utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1777. containedcritical

    Malware in @cloudways-lab/unified-design-system

    Malware was discovered in the npm package @cloudways-lab/unified-design-system. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1778. containedcritical

    Malware in @webda-infra-ui/static-images

    Malware was discovered in the npm package @webda-infra-ui/static-images. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1779. containedcritical

    Malware in autotel-backends

    Malware was discovered in the npm package autotel-backends. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1780. containedcritical

    Malware in autotel-cli

    The npm package autotel-cli was found to contain malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1781. containedcritical

    Malware in @bapiweb-ux/bapi-header

    Malware was discovered in the npm package @bapiweb-ux/bapi-header. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1782. containedcritical

    Malware in http-uploader-dev

    Malware was discovered in the npm package http-uploader-dev, providing full system compromise to any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1783. containedcritical

    Malware in @flipbit2-bb/test-auth-state

    Malware was discovered in the npm package @flipbit2-bb/test-auth-state. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1784. activecritical

    Malware in @flipbit2-bb/scope-test

    Malware discovered in the npm package @flipbit2-bb/scope-test. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1785. containedcritical

    Malware in hrb-cas-auth-js

    Malware was discovered in the npm package hrb-cas-auth-js. The package is considered to provide full system compromise to any computer where it is installed or running.

    npmCompromised package
  1786. containedcritical

    Malware in player-theming

    The npm package player-theming was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-j229-wx6p-5j43 was published on 2026-06-29.

    npmCompromised package
  1787. containedcritical

    Malware in player-core-ui

    Malware was discovered in the npm package player-core-ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1788. containedcritical

    Malware in cmp-api-stub

    Malware was discovered in the npm package cmp-api-stub. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1789. activecritical

    Malware in app-hotmart-blog-headless

    Malware discovered in the npm package app-hotmart-blog-headless. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1790. containedcritical

    Malware in hunsterx-package

    Malware was discovered in the npm package hunsterx-package, providing full system compromise to any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1791. containedcritical

    Malware in cdocs-data

    The npm package cdocs-data was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1792. containedcritical

    Malware in @shoobx/types

    Malware was discovered in the npm package @shoobx/types. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1793. activecritical

    Malware in @source-row/source-container

    Malware discovered in the npm package @source-row/source-container. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1794. containedcritical

    Malware in crossmint-wallets-sdk

    Malware was discovered in the npm package crossmint-wallets-sdk, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1795. containedcritical

    Malware in wac-atl-context

    The npm package wac-atl-context was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1796. containedcritical

    Malware in @gartnerx/gx-npm-messenger-util

    Malware was discovered in the npm package @gartnerx/gx-npm-messenger-util. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1797. activecritical

    Malware in @ataslkit/profilecard

    Malware discovered in the npm package @ataslkit/profilecard. Systems with this package installed are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1798. activecritical

    Malware in @shopbop/api-models

    Malware was discovered in the npm package @shopbop/api-models. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1799. activecritical

    Malware in ing-web-v5

    Malware discovered in the npm package ing-web-v5. The package grants full control of affected systems to an outside entity and should be considered a critical compromise.

    npmCompromised package
  1800. activecritical

    Malware in magwien.sys

    Malware discovered in the npm package magwien.sys. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1801. activecritical

    Malware in ltididp1

    The npm package ltididp1 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1802. containedcritical

    Malware in @experian-shared/services

    Malware was discovered in the npm package @experian-shared/services. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1803. containedcritical

    Malware in @gm-rvg/root-config

    Malware was discovered in the npm package @gm-rvg/root-config. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1804. containedcritical

    Malware in @lexisnexisrisk/insider-threat-platform

    Malware was discovered in the npm package @lexisnexisrisk/insider-threat-platform. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1805. activecritical

    Malware in kdrive-utils

    The npm package kdrive-utils contains malware that provides full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1806. activecritical

    Malware in zod-pino

    Malware discovered in the npm package zod-pino. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1807. activecritical

    Malware in hexo-deployer-wrangler

    Malware discovered in the npm package hexo-deployer-wrangler. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1808. activecritical

    Malware in prism-silq

    Malware discovered in the npm package prism-silq. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1809. activecritical

    Malware in ai-node-relay

    Malware discovered in the npm package ai-node-relay. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1810. activecritical

    Malware in rollup-plugin-polyfill-connect

    Malware discovered in the npm package rollup-plugin-polyfill-connect. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1811. resolvedcritical

    Malware in wellnpm

    The npm package wellnpm contained malware that provided full system compromise to attackers. Any system with the package installed or running should be considered fully compromised.

    npmCompromised package
  1812. containedcritical

    Malware in ref-slot

    Malware was discovered in the npm package ref-slot. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1813. activecritical

    Malware in package-uploader

    Malware discovered in the npm package package-uploader. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1814. containedcritical

    Malware in pump-stream-logger

    Malware was discovered in the npm package pump-stream-logger. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.

    npmCompromised package
  1815. containedcritical

    Malware in pino-zod

    Malware was discovered in the npm package pino-zod, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1816. activecritical

    Malware in ts-opus

    The npm package ts-opus contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1817. containedcritical

    Malware in analysis-chart

    The npm package analysis-chart was found to contain malware, resulting in full system compromise for any computer with the package installed or running. GitHub Security Advisory GHSA-2h56-6c2c-2475 was published on 2026-06-26.

    npmCompromised package
  1818. activecritical

    Malware in theme-color-picker

    The npm package theme-color-picker contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1819. containedcritical

    Malware in ttal2ttml

    The npm package ttal2ttml was found to contain malware, potentially giving outside entities full control of affected systems. All systems with this package installed should be considered fully compromised.

    npmCompromised package
  1820. activecritical

    Malware in pump-laserstream-parser

    Malware discovered in the npm package pump-laserstream-parser. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1821. containedcritical

    Malware in tw-style-utils

    Malware was discovered in the npm package tw-style-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1822. containedcritical

    Malware in vxui-react

    Malware was discovered in the npm package vxui-react, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.

    npmCompromised package
  1823. containedcritical

    Malware in weavedb-base

    Malware was discovered in the npm package weavedb-base. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1824. activecritical

    Malware in wao

    The npm package wao contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1825. containedcritical

    Malware in hexo-shoka-swiper

    Malware was discovered in the npm package hexo-shoka-swiper, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1826. activecritical

    Malware in ai-node-agent

    The npm package ai-node-agent contains malware that grants full system compromise to an outside entity. All systems with this package installed or running should be considered fully compromised.

    npmAI agents & skillsCompromised package
  1827. containedcritical

    Malware in react-icon-svgs

    The npm package react-icon-svgs was compromised and distributed with malware. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1828. activecritical

    Malware in easy-time666

    The npm package easy-time666 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1829. activecritical

    Malware in build-tracker-n5p1

    Malware discovered in the npm package build-tracker-n5p1. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1830. containedcritical

    Malware in ccl-component-resources

    Malware was discovered in the npm package ccl-component-resources. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1831. containedcritical

    Malware in leo-logger

    Malware was discovered in the npm package leo-logger, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a different computer.

    npmCompromised package
  1832. containedcritical

    Malware in leo-streams

    Malware was discovered in the npm package leo-streams. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1833. containedcritical

    Malware in leo-cache

    The npm package leo-cache was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.

    npmCompromised package
  1834. containedcritical

    Malware in leo-connector-mysql

    Malware was discovered in the npm package leo-connector-mysql. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1835. containedcritical

    Malware in rstreams-shard-util

    Malware was discovered in the npm package rstreams-shard-util, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1836. containedcritical

    Malware in leo-sdk

    Malware was discovered in the leo-sdk npm package. Systems with the package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1837. containedcritical

    Malware in serverless-convention

    Malware was discovered in the npm package serverless-convention. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1838. resolvedcritical

    Malware in serverless-leo

    Malware was discovered in the npm package serverless-leo. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1839. activecritical

    Malware in event-metrics-q3x7

    The npm package event-metrics-q3x7 contains malware that grants full system compromise to an outside entity. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1840. containedcritical

    Malware in boardflow

    Malware was discovered in the npm package boardflow, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1841. containedcritical

    Malware in leo-connector-elasticsearch

    Malware was discovered in the npm package leo-connector-elasticsearch. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1842. containedcritical

    Malware in leo-auth

    The npm package leo-auth was found to contain malware. Any system with the package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer, and the package should be removed.

    npmCompromised package
  1843. containedcritical

    Malware in solo-nav

    Malware was discovered in the npm package solo-nav, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1844. containedcritical

    Malware in leo-cron

    Malware was discovered in the leo-cron npm package. Systems with the package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1845. containedcritical

    Malware in leo-cli

    The npm package leo-cli was compromised and distributed with malware. Systems with the package installed or executed should be considered fully compromised and require complete remediation.

    npmCompromised package
  1846. containedcritical

    Malware in rstreams-metrics

    Malware was discovered in the npm package rstreams-metrics. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1847. containedcritical

    Malware in leo-connector-mongo

    Malware was discovered in the npm package leo-connector-mongo. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1848. containedcritical

    Malware in leo-connector-oracle

    Malware was discovered in the npm package leo-connector-oracle. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1849. activecritical

    Malware in pathfix

    The npm package pathfix contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1850. containedcritical

    Malware in easy-time-format

    Malware was discovered in the npm package easy-time-format. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1851. activecritical

    Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised

    On June 24, 2026, an attacker published malicious versions of 20 npm packages belonging to the Leo Platform ecosystem in a coordinated attack. All packages contained an identical CI/CD attack toolkit designed to steal secrets from GitHub Actions runners, cloud credential stores, package registries, and password managers, then exfiltrate them via the victim's GitHub token.

    npmOtherCompromised package
  1852. containedcritical

    Malware in @su-doughnym/metrics-js

    Malware was discovered in the npm package @su-doughnym/metrics-js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1853. containedcritical

    Malware in data-fetching-client

    Malware was discovered in the npm package data-fetching-client. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, uncompromised system.

    npmCompromised package
  1854. activecritical

    Malware in signup-embedder

    Malware discovered in the npm package signup-embedder. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1855. activecritical

    Malware in nabisco

    The npm package 'nabisco' contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1856. activecritical

    Malware in @su-doughnym/loginui

    Malware discovered in the npm package @su-doughnym/loginui. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1857. containedcritical

    Malware in nolimit-x

    The npm package nolimit-x was compromised and distributed with malware. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1858. containedcritical

    Malware in block-slot

    The npm package block-slot was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-pg29-x97h-gfr6 was published on 2026-06-25.

    npmCompromised package
  1859. containedcritical

    Malware in two-factor-prompt-lib

    Malware was discovered in the npm package two-factor-prompt-lib. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1860. activecritical

    Malware in hs-locale-management

    The npm package hs-locale-management contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised.

    npmCompromised package
  1861. activecritical

    Malware in @su-doughnym/react-dlb

    The npm package @su-doughnym/react-dlb contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  1862. containedcritical

    Malware in axl-ui

    Malware was discovered in the npm package axl-ui, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1863. containedcritical

    Malware in loadninja-shared

    Malware was discovered in the npm package loadninja-shared. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1864. containedcritical

    Malware in ts-grok

    Malware was discovered in the ts-grok npm package. Systems with the package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1865. containedcritical

    Malware in @su-doughnym/hubspot-loginui-poc

    The npm package @su-doughnym/hubspot-loginui-poc contained malware that provided full system compromise to attackers. All systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1866. activecritical

    Malware in atlassian-forge-skills

    The npm package atlassian-forge-skills contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1867. resolvedcritical

    Malware in poc-publish-test-su-doughnym

    Malware was discovered in the npm package poc-publish-test-su-doughnym. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  1868. activecritical

    Malware in @helpcentre/tesco-help

    The npm package @helpcentre/tesco-help contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1869. resolvedcritical

    Malware in rapidsearch

    The npm package rapidsearch contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package
  1870. containedcritical

    Malware in vercel-api-client

    Malware was discovered in the npm package vercel-api-client. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.

    npmCompromised package
  1871. activecritical

    Malware in pretie_x2

    The npm package pretie_x2 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1872. containedcritical

    Malware in evmdotjs

    The npm package evmdotjs was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1873. containedcritical

    Malware in @kl-dolphin/swim

    Malware was discovered in the npm package @kl-dolphin/swim, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1874. containedcritical

    Malware in @kl-dolphin/jump

    Malware was discovered in the npm package @kl-dolphin/jump, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1875. activecritical

    Malware in multer-express

    Malware was discovered in the npm package multer-express. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1876. activecritical

    Malware in pretie_x1

    The npm package pretie_x1 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1877. activecritical

    Malware in ui-core-system

    Malware discovered in the npm package ui-core-system. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1878. containedcritical

    Malware in ldapaotest

    The npm package ldapaotest was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.

    npmCompromised package
  1879. containedcritical

    Malware in react-campaign-optimizer

    Malware was discovered in the npm package react-campaign-optimizer. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1880. containedcritical

    Malware in runtime-query

    The npm package runtime-query was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-vh6x-853w-4qvp documents the incident.

    npmCompromised package
  1881. activecritical

    Malware in tailwind-textform-fill

    Malware discovered in the npm package tailwind-textform-fill. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1882. containedcritical

    Malware in normalize-plus

    Malware was discovered in the npm package normalize-plus, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1883. containedcritical

    Malware in fetch-page-assets

    Malware was discovered in the npm package fetch-page-assets. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1884. activecritical

    Malware in eth_accounts

    Malware was discovered in the eth_accounts npm package. Any computer with this package installed is considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  1885. containedcritical

    Malware in react-simple-utils-kit

    The npm package react-simple-utils-kit contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1886. activecritical

    Malware in node-vfs-polyfill

    Malware discovered in the npm package node-vfs-polyfill. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1887. activecritical

    Malware in aes-decode-runner-pro

    Malware discovered in the npm package aes-decode-runner-pro. Systems with this package installed are considered fully compromised and may have given outside entities complete control.

    npmCompromised package
  1888. activecritical

    Malware in markdownlint-cli2-fix

    Malware was discovered in the npm package markdownlint-cli2-fix. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1889. activecritical

    Malware in html-to-gutenberg

    The npm package html-to-gutenberg was found to contain malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1890. containedcritical

    Malware in date-format-helper2

    Malware was discovered in the npm package date-format-helper2. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1891. activecritical

    Malware in vscode-test-web

    Malware discovered in the npm package vscode-test-web. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1892. activecritical

    Malware in postcss-minify-selector

    Malware discovered in the npm package postcss-minify-selector. The package is considered to provide full system compromise to any computer where it is installed or running.

    npmCompromised package
  1893. containedcritical

    Malware in opt-archetype-check

    Malware was discovered in the npm package opt-archetype-check, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1894. activecritical

    Malware in postcss-minify-selector-parser

    Malware was discovered in the npm package postcss-minify-selector-parser. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1895. containedcritical

    Malware in poly-utils

    Malware was discovered in the npm package poly-utils. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1896. containedcritical

    Malware in web3-token-helper

    Malware was discovered in the npm package web3-token-helper. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1897. activecritical

    Malware in calculate-helper

    Malware discovered in the npm package calculate-helper. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.

    npmCompromised package
  1898. activecritical

    Malware in @ravespaceio/rave-engine

    Malware discovered in the npm package @ravespaceio/rave-engine. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1899. activecritical

    Malware in cursorai-agent

    Malware discovered in the npm package cursorai-agent. The package grants full control of affected systems to an outside entity and should be considered a complete system compromise.

    npmCompromised package
  1900. activecritical

    Malware in backoffice-charges-module

    Malware discovered in the npm package backoffice-charges-module. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1901. activecritical

    Malware in @muaththir/api

    Malware discovered in the npm package @muaththir/api. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1902. activecritical

    Malware in @ravespaceio/browser-input

    Malware discovered in the npm package @ravespaceio/browser-input. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1903. activecritical

    Malware in aillmgen

    Malware discovered in the npm package aillmgen. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  1904. containedcritical

    Malware in ts-arithmetic-helper

    Malware was discovered in the npm package ts-arithmetic-helper, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1905. activecritical

    Malware in parket-flow

    Malware discovered in the npm package parket-flow. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1906. resolvedcritical

    Malware in server-parket

    The npm package server-parket contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1907. containedcritical

    Malware in mjs-eslint-service

    Malware was discovered in the npm package mjs-eslint-service, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1908. containedcritical

    Malware in ts-sudo

    The npm package ts-sudo was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1909. resolvedcritical

    Malware in sync-external

    The npm package sync-external contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1910. activecritical

    Malware in chalk-ultra

    Malware discovered in the npm package chalk-ultra. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1911. containedcritical

    Malware in ts-predict-helper

    Malware was discovered in the npm package ts-predict-helper. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1912. containedcritical

    Malware in mjs-eslint-helper

    The npm package mjs-eslint-helper contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1913. activecritical

    Malware in vitest-cli

    Malware discovered in the npm package vitest-cli. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1914. activecritical

    Malware in chai-as-attested

    The npm package chai-as-attested contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  1915. containedcritical

    Malware in chai-as-uphelded

    The npm package chai-as-uphelded was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1916. containedcritical

    Malware in datacamp-light

    Malware was discovered in the npm package datacamp-light. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1917. activecritical

    Malware in libsignal-node-travatiger

    Malware discovered in the npm package libsignal-node-travatiger. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1918. activecritical

    Malware in ts-numbering

    Malware discovered in the npm package ts-numbering. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1919. activecritical

    Malware in onboarding-respects-modal

    Malware discovered in the npm package onboarding-respects-modal. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1920. containedcritical

    Malware in node-fetch-utils

    Malware was discovered in the npm package node-fetch-utils. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1921. containedcritical

    Malware in node-slot

    The npm package node-slot was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.

    npmCompromised package
  1922. resolvedcritical

    Malware in ts-wross

    The npm package ts-wross contained malware that provided full system compromise to attackers. Any computer with the package installed should be considered fully compromised and all secrets and keys rotated from a different machine.

    npmCompromised package
  1923. containedcritical

    Malware in node-core-libs

    Malware was discovered in the npm package node-core-libs. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1924. activecritical

    Malware in search-from-search

    The npm package search-from-search contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1925. containedcritical

    Malware in local-ip-helper

    The npm package local-ip-helper was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  1926. containedcritical

    Malware in crud-respect

    The npm package crud-respect was found to contain malware. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  1927. containedcritical

    Malware in setka-editor

    Malware was discovered in the npm package setka-editor, resulting in full system compromise of any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a different computer.

    npmCompromised package
  1928. activecritical

    Malware in carousel-controller-mixin

    Malware discovered in the npm package carousel-controller-mixin. The package grants full control of affected systems to an outside entity, requiring immediate removal and credential rotation from a clean machine.

    npmCompromised package
  1929. activecritical

    Malware in new-ecro-1

    The npm package new-ecro-1 contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1930. resolvedcritical

    Malware in new-solt

    The npm package new-solt was found to contain malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1931. containedcritical

    Malware in respects-switch

    The npm package respects-switch contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1932. resolvedcritical

    Malware in new-mjs-eslint

    The npm package new-mjs-eslint contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1933. resolvedcritical

    Malware in new-helper

    The npm package new-helper contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1934. resolvedcritical

    Malware in new-eslint-1

    Malware was distributed via the npm package new-eslint-1. Systems with this package installed or running should be considered fully compromised.

    npmCompromised package
  1935. activecritical

    Malware in new-ecro-helper

    The npm package new-ecro-helper contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1936. containedcritical

    Malware in new-ts-helper

    The npm package new-ts-helper contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1937. activecritical

    Malware in new-solt-1

    Malware discovered in the npm package new-solt-1. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1938. resolvedcritical

    Malware in eslint-helper-1

    Malware was discovered in the npm package eslint-helper-1, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1939. containedcritical

    Malware in free-claude

    The npm package free-claude contained malware that could fully compromise any system on which it was installed or running. GitHub Security Advisory GHSA-7qpf-5pm7-57rh documents the incident.

    npmCompromised package
  1940. activecritical

    Malware in mddriver

    The npm package mddriver contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1941. containedcritical

    Malware in node-path-utils

    Malware was discovered in the npm package node-path-utils. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1942. containedcritical

    Malware in free-anthropic-claude

    The npm package free-anthropic-claude contained malware that could fully compromise any system where it was installed or executed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  1943. containedhigh

    Microsoft links Mastra AI supply chain attack to North Korean hackers

    Microsoft attributed a Mastra AI supply chain attack that compromised over 140 npm packages to North Korean hacking group Sapphire Sleet (BlueNoroff). The attack targeted the npm ecosystem and AI development infrastructure.

    UNC1069npmAI agents & skillsCompromised packageMalicious maintainer
  1944. containedcritical

    Malware in ethereum-gas-reporter

    Malware was discovered in the ethereum-gas-reporter npm package. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  1945. activecritical

    15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers

    A coordinated 8-month supply chain attack compromised 15 malicious JetBrains plugins on the official JetBrains Marketplace, stealing AI API keys from approximately 70,000 developers. The credential-stealing code exfiltrated OpenAI, DeepSeek, and SiliconFlow API keys to an attacker-controlled server in Beijing, which remained operational at the time of disclosure.

    OtherCompromised packageMalicious maintainer
  1946. resolvedcritical

    Malware in assert-kit

    The npm package assert-kit contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1947. containedcritical

    Malware in pretty-logger-js

    Malware was discovered in the npm package pretty-logger-js. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  1948. activecritical

    Malware in mongoose-jsonify

    Malware discovered in the npm package mongoose-jsonify. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1949. containedcritical

    Malware in ts-ecro

    Malware was discovered in the npm package ts-ecro, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  1950. containedcritical

    Malware in ts-ecro-helper

    Malware was discovered in the npm package ts-ecro-helper. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  1951. resolvedcritical

    Malware in new-ecro

    The npm package new-ecro contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1952. containedcritical

    Malware in ts-big-ecro

    The npm package ts-big-ecro contained malware that fully compromised any system where it was installed. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  1953. containedcritical

    Malware in ts-esys

    Malware was discovered in the npm package ts-esys. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1954. containedcritical

    Malware in eth-util

    Malware was discovered in the eth-util npm package. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1955. resolvedcritical

    Malware in npm-sandbox-research-g3h4

    Malware was distributed via the npm package npm-sandbox-research-g3h4. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1956. containedcritical

    Malware in npm-sandbox-ping-r9t2

    Malware was discovered in the npm package npm-sandbox-ping-r9t2. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1957. containedcritical

    Malware in @ncurran/sandbox-recon-sys-5b2c

    Malware was discovered in the npm package @ncurran/sandbox-recon-sys-5b2c. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1958. containedcritical

    Malware in @ncurran/sandbox-recon-880538

    Malware was distributed via the npm package @ncurran/sandbox-recon-880538. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1959. containedcritical

    Malware in npm-sandbox-research-a1b2

    Malware was discovered in the npm package npm-sandbox-research-a1b2. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1960. activecritical

    Malware in pkg-telemetry-r4f9

    Malware discovered in the npm package pkg-telemetry-r4f9. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1961. containedcritical

    Malware in npm-sandbox-research-8b2f

    Malware was discovered in the npm package npm-sandbox-research-8b2f. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1962. resolvedcritical

    Malware in npm-sandbox-research-9c4e

    The npm package npm-sandbox-research-9c4e contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1963. containedcritical

    Malware in npm-sandbox-ping-c8f2a

    Malware was distributed via the npm package npm-sandbox-ping-c8f2a. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1964. activecritical

    Malware in metrics-pipeline-d8k2

    The npm package metrics-pipeline-d8k2 contains malware that provides full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1965. activecritical

    Malware in metrics-probe-dc85

    The npm package metrics-probe-dc85 contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1966. activecritical

    Malware in metrics-probe-77d4

    The npm package metrics-probe-77d4 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1967. containedcritical

    Malware in @ncurran/sandbox-recon-9b2d4f

    Malware was discovered in the npm package @ncurran/sandbox-recon-9b2d4f. Systems with this package installed or running should be considered fully compromised, requiring immediate credential rotation and package removal.

    npmCompromised package
  1968. containedcritical

    Malware in postinstall-logger-7x9z

    The npm package postinstall-logger-7x9z contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1969. containedcritical

    Malware in type-check-816d

    The npm package type-check-816d was found to contain malware, potentially providing full system compromise to attackers. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  1970. containedcritical

    Malware in metrics-probe-f256

    The npm package metrics-probe-f256 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1971. containedcritical

    Malware in @ncurran/sandbox-recon-uac-4e7c

    The npm package @ncurran/sandbox-recon-uac-4e7c contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  1972. activecritical

    Malware in data-utils-d703

    The npm package data-utils-d703 contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1973. resolvedcritical

    Malware in npm-sandbox-research-f1g2

    Malware was discovered in the npm package npm-sandbox-research-f1g2. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  1974. activecritical

    Malware in metrics-probe-88ad

    The npm package metrics-probe-88ad contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1975. activecritical

    Malware in runtime-metrics-w7k2

    Malware discovered in the npm package runtime-metrics-w7k2. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1976. containedcritical

    Malware in string-tools-be6c

    The npm package string-tools-be6c contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated from a different machine.

    npmCompromised package
  1977. containedcritical

    Malware in intquery

    The npm package intquery was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  1978. activecritical

    Malware in @rafaelsene01/agent-flow

    Malware discovered in the npm package @rafaelsene01/agent-flow. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  1979. containedcritical

    Malware in uidai_reusable_components

    Malware was discovered in the npm package uidai_reusable_components. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1980. activecritical

    Malware in @ncurran/sandbox-recon-sys-5f1b

    Malware discovered in the npm package @ncurran/sandbox-recon-sys-5f1b. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1981. containedcritical

    Malware in parket-slot

    Malware was discovered in the npm package parket-slot, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.

    npmCompromised package
  1982. activecritical

    Malware in metrics-probe-64b2

    The npm package metrics-probe-64b2 contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  1983. resolvedcritical

    Malware in @ncurran/dc-selftest-33afb7

    The npm package @ncurran/dc-selftest-33afb7 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised.

    npmCompromised package
  1984. containedcritical

    Malware in @ncurran/sandbox-recon-sys-6a3f

    Malware was discovered in the npm package @ncurran/sandbox-recon-sys-6a3f. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1985. resolvedcritical

    Malware in @ncurran/dc-selftest-ba0ad4

    The npm package @ncurran/dc-selftest-ba0ad4 contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1986. activecritical

    Malware in color-utils-dee0

    The npm package color-utils-dee0 contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  1987. resolvedcritical

    Malware in npm-sandbox-research-d7e8

    Malware was distributed via the npm package npm-sandbox-research-d7e8. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  1988. activecritical

    Malware in fmt-helpers-794b

    The npm package fmt-helpers-794b contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  1989. containedcritical

    Malware in parket-helper

    Malware was distributed via the parket-helper npm package. Systems with the package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1990. containedcritical

    Malware in @ncurran/sandbox-recon-7c4e1a

    Malware was discovered in the npm package @ncurran/sandbox-recon-7c4e1a. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  1991. resolvedcritical

    Malware in npm-sandbox-research-e9f0

    Malware was discovered in the npm package npm-sandbox-research-e9f0. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  1992. resolvedcritical

    Malware in npm-sandbox-research-c5d6

    Malware was distributed via the npm package npm-sandbox-research-c5d6. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  1993. activecritical

    Malware in @mastra/voice-playai

    Malware was discovered in the npm package @mastra/voice-playai. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  1994. activecritical

    Malware in express-validates

    The npm package express-validates was compromised and contains malware. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1995. activecritical

    Malware in qrcode-express

    Malware discovered in the npm package qrcode-express. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1996. activecritical

    Malware in sodel-pych

    Malware discovered in the npm package sodel-pych. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1997. containedcritical

    Malware in api-rs-node

    Malware was discovered in the npm package api-rs-node. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from a clean system.

    npmCompromised package
  1998. activecritical

    Malware in @mastra/loggers

    Malware was discovered in the npm package @mastra/loggers. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  1999. containedcritical

    Malware in @mastra/observability

    Malware was discovered in the npm package @mastra/observability. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2000. containedcritical

    Malware in @mastra/blaxel

    Malware was discovered in the npm package @mastra/blaxel. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2001. activecritical

    Malware in @mastra/agent-builder

    Malware was discovered in the npm package @mastra/agent-builder. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  2002. containedcritical

    Malware in @mastra/stagehand

    Malware was discovered in the npm package @mastra/stagehand. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2003. activecritical

    Malware in @mastra/tavily

    Malware was discovered in the npm package @mastra/tavily. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2004. activecritical

    Malware in @mastra/claude

    The npm package @mastra/claude contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2005. activecritical

    Malware in @mastra/otel-exporter

    Malware was discovered in the npm package @mastra/otel-exporter. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2006. activecritical

    Malware in @mastra/deployer-vercel

    Malware discovered in the npm package @mastra/deployer-vercel. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2007. activecritical

    Malware in chai-as-tokenized

    Malware discovered in the npm package chai-as-tokenized. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2008. resolvedcritical

    Malware in @ignacionunez91/keccak24

    Malware was discovered in the npm package @ignacionunez91/keccak24. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2009. containedcritical

    Malware in @mastra/pinecone

    Malware was discovered in the npm package @mastra/pinecone. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2010. containedcritical

    Malware in sort-btree

    Malware was discovered in the npm package sort-btree, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2011. activecritical

    Malware in @mastra/node-speaker

    Malware was discovered in the npm package @mastra/node-speaker. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2012. activecritical

    Malware in @mastra/node-audio

    Malware was discovered in the npm package @mastra/node-audio. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2013. activecritical

    Malware in @mastra/arize

    Malware was discovered in the npm package @mastra/arize. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2014. containedcritical

    Malware in @mastra/gcs

    Malware was discovered in the npm package @mastra/gcs. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2015. activecritical

    Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosquat

    On June 17, 2026, an attacker compromised the @mastra npm organization and injected easy-day-js, a typosquat of the popular dayjs library, as a dependency across 140+ packages. The malicious package contained an obfuscated postinstall dropper that downloaded and executed a second-stage payload from attacker-controlled servers before self-deleting. The affected packages had a combined weekly download count exceeding 1.1 million.

    npmCompromised packageTyposquattingMalicious maintainer
  2016. activecritical

    Malware in @mastra/convex

    Malware was discovered in the npm package @mastra/convex. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2017. activecritical

    Malware in @mastra/s3vectors

    Malware was discovered in the npm package @mastra/s3vectors. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2018. containedcritical

    Malware in @mastra/upstash

    Malware was discovered in the npm package @mastra/upstash. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2019. containedcritical

    Malware in @mastra/deployer-cloudflare

    Malware was discovered in the npm package @mastra/deployer-cloudflare. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2020. containedcritical

    Malware in @mastra/cloudflare

    Malware was discovered in the npm package @mastra/cloudflare. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.

    npmCompromised package
  2021. activecritical

    Malware in @mastra/cursor

    Malware discovered in the npm package @mastra/cursor. Systems with this package installed are considered fully compromised with potential for complete system control by external entities.

    npmCompromised package
  2022. activecritical

    Malware in @mastra/deployer-netlify

    Malware discovered in the npm package @mastra/deployer-netlify. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2023. activecritical

    Malware in @mastra/turbopuffer

    Malware was discovered in the npm package @mastra/turbopuffer. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2024. activecritical

    Malware in @mastra/playground-ui

    Malware was discovered in the npm package @mastra/playground-ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2025. activecritical

    Malware in @mastra/agent-browser

    Malware was discovered in the npm package @mastra/agent-browser. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmAI agents & skillsCompromised package
  2026. activecritical

    Malware in @mastra/temporal

    Malware was discovered in the npm package @mastra/temporal. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2027. containedcritical

    Malware in @mastra/mcp-registry-registry

    Malware was discovered in the npm package @mastra/mcp-registry-registry. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2028. activecritical

    Malware in @mastra/longmemeval

    Malware was discovered in the npm package @mastra/longmemeval. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2029. containedcritical

    Malware in @mastra/daytona

    Malware was discovered in the npm package @mastra/daytona. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2030. activecritical

    Malware in @mastra/voice-google-gemini-live

    Malware discovered in the npm package @mastra/voice-google-gemini-live. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2031. activecritical

    Malware in @mastra/google-cloud-pubsub

    Malware was discovered in the npm package @mastra/google-cloud-pubsub. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2032. activecritical

    Malware in @mastra/voice-openai-realtime

    Malware was discovered in the npm package @mastra/voice-openai-realtime. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2033. activecritical

    Malware in @mastra/voice-openai

    Malware was discovered in the npm package @mastra/voice-openai. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2034. activecritical

    Malware in qrcode-generator-node

    Malware was discovered in the npm package qrcode-generator-node. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2035. containedcritical

    Malware in @mastra/voice-google

    Malware was discovered in the npm package @mastra/voice-google. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2036. activecritical

    Malware in @mastra/voice-aws-nova-sonic

    Malware was discovered in the npm package @mastra/voice-aws-nova-sonic. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2037. activecritical

    Malware in @mastra/voice-deepgram

    Malware was discovered in the npm package @mastra/voice-deepgram. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover by an external entity.

    npmCompromised package
  2038. activecritical

    Malware in @mastra/e2b

    Malware discovered in the npm package @mastra/e2b. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2039. activecritical

    Malware in @mastra/voice-elevenlabs

    Malware was discovered in the npm package @mastra/voice-elevenlabs. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2040. activecritical

    Malware in @mastra/react

    Malware was discovered in the npm package @mastra/react. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2041. activecritical

    Malware in @mastra/docker

    Malware was discovered in the npm package @mastra/docker. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2042. activecritical

    Malware in @mastra/redis

    Malware was discovered in the npm package @mastra/redis. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2043. activecritical

    Malware in @mastra/mem0

    Malware was discovered in the npm package @mastra/mem0. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2044. containedcritical

    Malware in @mastra/github-signals

    Malware was discovered in the npm package @mastra/github-signals. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2045. activecritical

    Malware in tailwindcss-animates-css

    Malware discovered in the npm package tailwindcss-animates-css. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2046. containedcritical

    Malware in terminal-structured-logger

    Malware was discovered in the npm package terminal-structured-logger. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2047. activecritical

    Malware in check-ulid

    The npm package check-ulid was compromised and contains malware. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2048. containedcritical

    Malware in rbac-auth

    Malware was discovered in the npm package rbac-auth. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2049. containedcritical

    Malware in bign.tsm

    The npm package bign.tsm was found to contain malware. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2050. containedcritical

    Malware in authcascade

    Malware was discovered in the npm package authcascade, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2051. containedcritical

    Malware in npmjs-doc-builder

    The npm package npmjs-doc-builder was found to contain malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2052. containedcritical

    Malware in sp-api-dev-assistant-mcp-server

    Malware was discovered in the npm package sp-api-dev-assistant-mcp-server. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different system.

    npmCompromised package
  2053. containedcritical

    Malware in ttspc-server-sample

    The npm package ttspc-server-sample contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2054. containedcritical

    Malware in janus-flow

    Malware was discovered in the npm package janus-flow, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2055. containedcritical

    Malware in flow-lending

    The npm package flow-lending was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-pgcr-8w67-72j9 was published on 2026-06-16.

    npmCompromised package
  2056. containedcritical

    Malware in janus-ft

    The npm package janus-ft was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2057. containedcritical

    Malware in flowdefi

    Malware was discovered in the npm package flowdefi. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  2058. containedcritical

    Malware in flowcardano

    Malware was discovered in the npm package flowcardano. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2059. containedcritical

    Malware in bodega-sdk

    The npm package bodega-sdk was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2060. activecritical

    Malware in websocket-slot

    The npm package websocket-slot contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2061. activecritical

    Malware in epm-service-module-v2

    Malware discovered in the npm package epm-service-module-v2. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2062. containedcritical

    Malware in hot-validation-sdk

    Malware was discovered in the npm package hot-validation-sdk. The advisory warns that any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2063. containedcritical

    Malware in worker-build

    Malware was discovered in the npm package worker-build, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal and rotation of all secrets and keys from a clean system.

    npmCompromised package
  2064. activecritical

    Malware in pampipes

    Malware discovered in the npm package pampipes. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2065. activecritical

    Malware in auth-basic-vault

    Malware discovered in the npm package auth-basic-vault. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2066. containedcritical

    Malware in lucide-next

    Malware was discovered in the lucide-next npm package. Systems with the package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2067. activecritical

    Malware in swplayer-react-sl

    The npm package swplayer-react-sl contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2068. containedcritical

    Malware in janus-erc20

    Malware was discovered in the npm package janus-erc20. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2069. containedcritical

    Malware in flow-lending-sdk

    Malware was discovered in the npm package flow-lending-sdk. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2070. containedcritical

    Malware in tailwind-typography-style

    The npm package tailwind-typography-style contained malware that could fully compromise any system where it was installed. All secrets and keys on affected systems should be rotated immediately, and the package should be removed.

    npmCompromised package
  2071. containedcritical

    Malware in simple-auth-basic

    The npm package simple-auth-basic was compromised and distributed with malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2072. activecritical

    Malware in fabric-graphics

    The npm package fabric-graphics contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2073. containedcritical

    Malware in surf-lending

    Malware was discovered in the npm package surf-lending. Any system with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2074. containedcritical

    Malware in terminal-pretty-logger

    Malware was discovered in the npm package terminal-pretty-logger. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2075. activecritical

    Malware in prettier_v1

    Malware was discovered in the npm package prettier_v1. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  2076. activecritical

    Malware in @monitoring-lib/error-tracking

    Malware discovered in the npm package @monitoring-lib/error-tracking. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2077. activecritical

    Malware in browserslist-db-sync

    Malware was discovered in the npm package browserslist-db-sync, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2078. activecritical

    Malware in ect-472839-ctf

    The npm package ect-472839-ctf contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2079. activecritical

    Malware in vite-enhancer-config

    The npm package vite-enhancer-config contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2080. resolvedcritical

    Malware in sn-internal-testjgsakjdkjadkjahsdkjad

    Malware was distributed via the npm package sn-internal-testjgsakjdkjadkjahsdkjad. Installation of this package results in full system compromise. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2081. activecritical

    Malware in internallib_v557

    Malware discovered in the npm package internallib_v557. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2082. resolvedcritical

    Malware in sb-original

    The npm package sb-original contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2083. containedcritical

    Malware in vemos-sdk

    The npm package vemos-sdk was found to contain malware, resulting in full system compromise for any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2084. activecritical

    Malware in web-model-bridge

    Malware discovered in the npm package web-model-bridge. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2085. containedcritical

    Malware in sn-internal-test

    The npm package sn-internal-test was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2086. activecritical

    Malware in vite-configu-react

    Malware discovered in the npm package vite-configu-react. The package grants full control of affected systems to an outside entity and compromises all secrets and keys stored on those systems.

    npmCompromised package
  2087. activecritical

    Malware in ect-839201

    The npm package ect-839201 contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2088. activecritical

    Malware in vite-config-react

    The npm package vite-config-react contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2089. activecritical

    Malware in ecto_module

    Malware discovered in the npm package ecto_module. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2090. activecritical

    Malware in ect-472839

    The npm package ect-472839 contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2091. activecritical

    Malware in ect-839201-ctf

    The npm package ect-839201-ctf contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2092. containedcritical

    Malware in index-ulid

    The npm package index-ulid was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2093. activecritical

    Malware in internallib_v984

    Malware discovered in the npm package internallib_v984. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2094. activecritical

    Malware in internallib_v856

    Malware discovered in the npm package internallib_v856. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2095. activecritical

    Malware in mermaid-v11

    Malware discovered in the npm package mermaid-v11. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2096. resolvedcritical

    Malware in slow-surf

    The npm package slow-surf contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2097. activecritical

    Malware in chai-smart-assert

    Malware discovered in the npm package chai-smart-assert. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2098. containedcritical

    Malware in shopify-app-bridge-internal

    Malware was discovered in the npm package shopify-app-bridge-internal. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2099. activecritical

    Malware in richtext-editor-ui

    The npm package richtext-editor-ui contains malware that grants full system compromise to an outside entity. All systems with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2100. activecritical

    Malware in ect-654321

    Malware discovered in the npm package ect-654321. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2101. containedcritical

    Malware in reading-cookies

    The npm package reading-cookies was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and require immediate remediation.

    npmCompromised package
  2102. containedcritical

    Malware in optional-cpu-features

    Malware was discovered in the npm package optional-cpu-features. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2103. activecritical

    Malware in prettier_v2

    Malware discovered in the npm package prettier_v2. Installation results in full system compromise with potential for complete control by external actors.

    npmCompromised package
  2104. activecritical

    Malware in numdifftools

    Malware discovered in the npm package numdifftools. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2105. activecritical

    Malware in um4r719-baileys

    The npm package um4r719-baileys contains malware that grants full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  2106. activecritical

    Malware in web-dotenv

    Malware discovered in the npm package web-dotenv. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2107. activecritical

    Malware in ecto-spirit-win-k4n8

    Malware discovered in the npm package ecto-spirit-win-k4n8. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2108. activecritical

    Malware in ecto-flag-read-m7p2

    The npm package ecto-flag-read-m7p2 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2109. containedcritical

    Malware in ecto-spectral-leak-8d4e2

    Malware was discovered in the npm package ecto-spectral-leak-8d4e2. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2110. activecritical

    Malware in ecto-win-flag-q2m7

    Malware discovered in the npm package ecto-win-flag-q2m7. Systems with this package installed are considered fully compromised and may have given outside entities complete control.

    npmCompromised package
  2111. containedcritical

    Malware in sea-bound-siren

    The npm package sea-bound-siren contained malware that fully compromised any system where it was installed or running. The package has been identified and removed from distribution.

    npmCompromised package
  2112. activecritical

    Malware in ecto-corsair-flag-x9m4

    Malware discovered in the npm package ecto-corsair-flag-x9m4. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2113. activecritical

    Malware in chai-web3-testkit

    Malware was discovered in the npm package chai-web3-testkit. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2114. activecritical

    Malware in ecto-rust-read-f3a9c1

    Malware was discovered in the npm package ecto-rust-read-f3a9c1. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2115. activecritical

    Malware in ecto-nightly-spirit

    The npm package ecto-nightly-spirit contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2116. activecritical

    Malware in ecto-corsair-whisper-6f3b9

    Malware discovered in the npm package ecto-corsair-whisper-6f3b9. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2117. containedcritical

    Malware in coral-wraith

    Malware was discovered in the npm package coral-wraith. Systems with the package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2118. resolvedcritical

    Malware in @malwguy/ecto-corsair-whisper-3d2a7c

    The npm package @malwguy/ecto-corsair-whisper-3d2a7c contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2119. containedcritical

    Malware in vite-react-toolkit

    The npm package vite-react-toolkit contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2120. activecritical

    Malware in transportator

    The npm package transportator contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2121. resolvedcritical

    Malware in @tenforce/toolbox-fontmap

    Malware was discovered in the npm package @tenforce/toolbox-fontmap, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  2122. containedcritical

    Malware in @ntnx/nx-react-components

    Malware was discovered in the npm package @ntnx/nx-react-components. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2123. resolvedcritical

    Malware in downlynpm

    The npm package downlynpm contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately.

    npmCompromised package
  2124. resolvedcritical

    Malware in @johntaohunter/forge-jsx

    Malware was discovered in the npm package @johntaohunter/forge-jsx. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  2125. containedcritical

    Malware in ozonex-sdk

    Malware was discovered in the npm package ozonex-sdk. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2126. containedcritical

    Malware in ozone-sdk

    Malware was discovered in the npm package ozone-sdk, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  2127. activecritical

    Malware in forge-jsxy

    The npm package forge-jsxy contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2128. containedcritical

    Malware in sass-formats

    Malware was discovered in the npm package sass-formats. The package is considered to provide full system compromise to any computer where it is installed or running.

    npmCompromised package
  2129. activecritical

    Malware in typeorm-encrypt

    Malware discovered in the npm package typeorm-encrypt. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2130. activecritical

    Malware in @trackking/core

    Malware discovered in the npm package @trackking/core. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2131. containedcritical

    Malware in emittery_styled

    The npm package emittery_styled was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2132. containedcritical

    Malware in @serviceshub/x-web-core

    Malware was discovered in the npm package @serviceshub/x-web-core. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2133. containedcritical

    Malware in @ngt-frontend/widgets-core

    Malware was discovered in the npm package @ngt-frontend/widgets-core. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2134. activecritical

    Malware in @vivaux/telemetry

    Malware was discovered in the npm package @vivaux/telemetry. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2135. activecritical

    Malware in @tribe-digital/shopify-starter-theme

    Malware was discovered in the npm package @tribe-digital/shopify-starter-theme. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2136. containedcritical

    Malware in @vtmn-play/react

    Malware was discovered in the npm package @vtmn-play/react. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2137. containedcritical

    Malware in @sazka/web

    The npm package @sazka/web contained malware that could fully compromise any system where it was installed or running. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a different computer.

    npmCompromised package
  2138. containedcritical

    Malware in @marketplace-shared/components

    Malware was discovered in the npm package @marketplace-shared/components. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2139. activecritical

    Malware in @hatcha-captcha/core

    Malware discovered in the npm package @hatcha-captcha/core. Systems with this package installed are considered fully compromised with potential for complete system takeover.

    npmCompromised package
  2140. resolvedcritical

    Malware in zatzdbai

    The npm package zatzdbai contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2141. containedcritical

    Malware in hex-type

    The npm package hex-type was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-jc42-pxfc-29x3 was published on 2026-06-11.

    npmCompromised package
  2142. activecritical

    Malware in @iobeya/spa-auth

    Malware discovered in the npm package @iobeya/spa-auth. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2143. containedcritical

    Malware in tailwindcss-animatics

    Malware was discovered in the npm package tailwindcss-animatics. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.

    npmCompromised package
  2144. containedcritical

    Malware in tailwindcss-merge

    Malware was discovered in the npm package tailwindcss-merge, potentially compromising any system with the package installed. The advisory recommends treating affected systems as fully compromised and rotating all secrets and keys from a clean machine.

    npmCompromised package
  2145. resolvedcritical

    Malware in crypto-javascript

    Malware was discovered in the npm package crypto-javascript. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2146. containedcritical

    Malware in rate-limits-flexible

    The npm package rate-limits-flexible was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2147. containedcritical

    Malware in rate-limit-flexible

    Malware was discovered in the npm package rate-limit-flexible. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2148. containedcritical

    Malware in sass-format

    The npm package sass-format was compromised and distributed with malware. Any system with the package installed or running should be considered fully compromised.

    npmCompromised package
  2149. containedcritical

    Malware in tailwindcss-animotion

    Malware was discovered in the npm package tailwindcss-animotion. The package grants full system compromise to attackers, requiring immediate removal and credential rotation from unaffected systems.

    npmCompromised package
  2150. containedcritical

    Malware in clsx-tailwind

    Malware was discovered in the npm package clsx-tailwind. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2151. activecritical

    Malware in tailwindcss-animates-kit

    Malware discovered in the npm package tailwindcss-animates-kit. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2152. containedcritical

    Malware in swagger-express-routes

    Malware was discovered in the npm package swagger-express-routes. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.

    npmCompromised package
  2153. containedcritical

    Malware in routing-controls

    The npm package routing-controls was compromised and distributed with malware. Any system with the package installed or running should be considered fully compromised.

    npmCompromised package
  2154. activecritical

    Malware in react-photo-views

    Malware was discovered in the npm package react-photo-views. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2155. containedcritical

    Malware in experian-analytics-components

    Malware was discovered in the npm package experian-analytics-components. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2156. activecritical

    Malware in justgetit

    The npm package justgetit contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2157. containedcritical

    Malware in @common-stack/generate-plugin

    Malware was distributed via the npm package @common-stack/generate-plugin. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2158. containedcritical

    Malware in fed-callnative

    Malware was discovered in the npm package fed-callnative. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2159. containedcritical

    Malware in theta-sdk

    The npm package theta-sdk was compromised and distributed with malware. Any system with the package installed or running should be considered fully compromised.

    npmCompromised package
  2160. activecritical

    Malware in google-cloud-secret-manager-config-poc

    Malware was discovered in the npm package google-cloud-secret-manager-config-poc. Systems with this package installed should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2161. containedcritical

    Malware in rsflows-pexml

    Malware was discovered in the npm package rsflows-pexml, resulting in full system compromise for any computer with the package installed or running. The package should be removed and all secrets and keys rotated from a different computer.

    npmCompromised package
  2162. containedcritical

    Malware in sensivity

    The npm package sensivity was found to contain malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2163. containedcritical

    Malware in polymarket-clob-api

    Malware was discovered in the npm package polymarket-clob-api, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2164. containedcritical

    Malware in vqlxjmpr

    The npm package vqlxjmpr contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2165. resolvedcritical

    Malware in @snowsight/debug-tooling

    The npm package @snowsight/debug-tooling contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2166. activecritical

    Malware in @integrations-center/utils

    Malware discovered in the npm package @integrations-center/utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2167. containedcritical

    Malware in @visma-net-platform/module-navigator

    Malware was discovered in the npm package @visma-net-platform/module-navigator. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  2168. containedcritical

    Malware in tailwind-dark-mode-kit

    Malware was discovered in the npm package tailwind-dark-mode-kit. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2169. activecritical

    Malware in ioredis-typed

    Malware discovered in the npm package ioredis-typed. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2170. activecritical

    Malware in ioredis-orm

    Malware was discovered in the npm package ioredis-orm. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a separate, uncompromised system.

    npmCompromised package
  2171. containedcritical

    Malware in @web-3d-tool/sdk

    Malware was discovered in the npm package @web-3d-tool/sdk, resulting in full system compromise for any computer with the package installed or running. The advisory recommends immediate removal of the package and rotation of all secrets and keys from a different computer.

    npmCompromised package
  2172. activecritical

    Malware in forge-jsx2

    Malware discovered in the npm package forge-jsx2. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2173. containedcritical

    Malware in archetype-style

    The npm package archetype-style was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-m9f5-cp7r-48pm documents the incident.

    npmCompromised package
  2174. resolvedcritical

    Malware in mm-ts-utils-client

    Malware was discovered in the npm package mm-ts-utils-client. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2175. containedcritical

    Malware in pui-diagnostics

    Malware was discovered in the npm package pui-diagnostics. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2176. containedcritical

    Malware in tw-fluid-type

    Malware was discovered in the npm package tw-fluid-type. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2177. containedcritical

    Malware in apple-mycelium-fix

    Malware was discovered in the npm package apple-mycelium-fix. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2178. containedcritical

    Malware in @coterie-baby/common

    Malware was discovered in the npm package @coterie-baby/common. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2179. activecritical

    Malware in sitecore-mm-component-style

    Malware discovered in the npm package sitecore-mm-component-style. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2180. containedcritical

    Malware in paypal-payouts-bridge

    Malware was discovered in the npm package paypal-payouts-bridge. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2181. containedcritical

    Malware in crypto-hash-sdk

    Malware was discovered in the npm package crypto-hash-sdk. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2182. activecritical

    Malware in tailwind-animator

    Malware discovered in the npm package tailwind-animator. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2183. containedcritical

    Malware in prettier-sdk

    Malware was discovered in the npm package prettier-sdk, resulting in full system compromise for any installation. The package grants outside entities complete control of affected systems.

    npmCompromised package
  2184. activecritical

    Malware in csc154-internall-depend

    Malware discovered in the npm package csc154-internall-depend. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2185. containedcritical

    Malware in crypto-promise-js

    Malware was distributed via the npm package crypto-promise-js. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2186. activecritical

    Malware in @easytipsportal/pos-adapters

    Malware discovered in the npm package @easytipsportal/pos-adapters. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2187. activecritical

    Malware in get-deps-path

    The npm package get-deps-path contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2188. resolvedcritical

    Malware in argoncrypt

    The npm package argoncrypt was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2189. activecritical

    Malware in @meme-sdk/trade

    Malware discovered in the npm package @meme-sdk/trade. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2190. activecritical

    Malware in @validate-sdk/v2

    The npm package @validate-sdk/v2 contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2191. activecritical

    Malware in ethers-jss

    Malware discovered in the npm package ethers-jss. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2192. containedcritical

    Malware in coinbase-wallet-utils

    Malware was discovered in the npm package coinbase-wallet-utils. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2193. activecritical

    Malware in @solana-launchpad/sdk

    Malware discovered in the npm package @solana-launchpad/sdk. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2194. resolvedcritical

    Malware in devkitx

    The npm package devkitx contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package
  2195. activecritical

    Malware in solidity-abi

    Malware discovered in the npm package solidity-abi. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2196. containedcritical

    Malware in npmjs_hardhat-common

    Malware was distributed via the npmjs_hardhat-common package on npm. Any computer with this package installed should be considered fully compromised.

    npmCompromised package
  2197. activecritical

    Malware in @easytipsportal/node-helper

    Malware discovered in the npm package @easytipsportal/node-helper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2198. containedcritical

    Malware in graphbase-js

    Malware was discovered in the npm package graphbase-js. Systems with the package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2199. activecritical

    Malware in npmjs_web3-common

    Malware was discovered in the npm package web3-common. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2200. activecritical

    Malware in @validator-sdk/pubkey

    Malware discovered in the npm package @validator-sdk/pubkey. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2201. containedcritical

    Malware in anaylze-json

    Malware was discovered in the npm package anaylze-json. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2202. containedcritical

    Malware in security-env-loader

    The npm package security-env-loader contained malware that could fully compromise any system where it was installed or executed. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2203. containedcritical

    Malware in @validate-ethereum-address/core

    The npm package @validate-ethereum-address/core was found to contain malware, potentially giving attackers full control of affected systems. Any computer with this package installed should be considered fully compromised.

    npmCompromised package
  2204. containedcritical

    Malware in xnder-sdk

    Malware was discovered in the npm package xnder-sdk, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  2205. activecritical

    Malware in xnder-wrapper-module

    Malware discovered in the npm package xnder-wrapper-module. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2206. activecritical

    Malware in martinez-polygon-clipping-simul-dalton

    The npm package martinez-polygon-clipping-simul-dalton contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2207. containedcritical

    Malware in auth0-templates-scripts-utils

    Malware was discovered in the npm package auth0-templates-scripts-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2208. resolvedcritical

    Malware in nw-demo

    The npm package nw-demo contained malware that could fully compromise any system where it was installed or executed. GitHub Security Advisory GHSA-hmxw-6c9h-v2h2 was published on 2026-06-10 to alert users of the threat.

    npmCompromised package
  2209. containedcritical

    Malware in npmjs_ethers-common

    Malware was discovered in the npm package ethers-common. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2210. activecritical

    Malware in plugin-fastify

    Malware discovered in the npm package plugin-fastify. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2211. containedcritical

    Malware in nw-demo-utils

    Malware was discovered in the npm package nw-demo-utils. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2212. containedcritical

    Malware in npmjs_truffle-helper

    Malware was discovered in the npm package npmjs_truffle-helper. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2213. containedcritical

    Malware in ethers-wordlist

    Malware was discovered in the npm package ethers-wordlist. Systems with this package installed are considered fully compromised and require immediate remediation including key rotation and package removal.

    npmCompromised package
  2214. containedcritical

    Malware in npmjs_solc-helper

    The npm package npmjs_solc-helper contained malware, potentially granting full system compromise to attackers. Any system with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2215. activecritical

    Malware in npmjs_web3-util

    Malware discovered in the npm package web3-util. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2216. containedcritical

    Malware in solc-compiler

    The npm package solc-compiler was found to contain malware. Any system with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package
  2217. containedcritical

    Malware in solc-abi

    Malware was discovered in the npm package solc-abi, affecting any system with the package installed. The compromise is considered critical, with full system compromise possible.

    npmCompromised package
  2218. containedcritical

    Malware in auth0-templates-scripts

    Malware was discovered in the npm package auth0-templates-scripts. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2219. activecritical

    Malware in python-utils

    The npm package python-utils was compromised and distributed with malware. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2220. activecritical

    Malware in use-context-selector-tony

    The npm package use-context-selector-tony contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  2221. activecritical

    Malware in martinez-polygon-clipping-tony

    Malware discovered in the npm package martinez-polygon-clipping-tony. The package grants full system compromise to attackers and should be considered a critical threat to any system where it is installed or running.

    npmCompromised package
  2222. containedcritical

    Malware in react-tracked-tony

    Malware was discovered in the npm package react-tracked-tony. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2223. containedcritical

    Malware in @builder.io/dev-tools

    Malware was discovered in the npm package @builder.io/dev-tools, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2224. activecritical

    Malware in @doaction/auth

    Malware discovered in the npm package @doaction/auth. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2225. containedcritical

    Malware in comos-sdk

    Malware was discovered in the npm package comos-sdk, resulting in full system compromise for any installation. The package should be removed and all secrets and keys rotated from a clean system.

    npmCompromised package
  2226. activecritical

    Malware in path-extend

    The npm package path-extend contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2227. containedcritical

    Malware in void-ulid

    Malware was discovered in the npm package void-ulid, resulting in full system compromise for any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  2228. containedcritical

    Malware in @doaction/shared

    Malware was discovered in the npm package @doaction/shared. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2229. containedcritical

    Malware in @doaction/http

    Malware was discovered in the npm package @doaction/http. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2230. containedcritical

    Malware in @doaction/storage

    Malware was discovered in the npm package @doaction/storage. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.

    npmCompromised package
  2231. activecritical

    Malware in @doaction/sudo-prompt

    Malware was discovered in the npm package @doaction/sudo-prompt. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2232. containedcritical

    Malware in @doaction/types

    Malware was discovered in the npm package @doaction/types. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2233. activecritical

    Malware in clsx-js

    Malware discovered in the npm package clsx-js. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2234. containedcritical

    Malware in os-ulid-void

    The npm package os-ulid-void was found to contain malware, potentially providing full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2235. containedcritical

    Malware in ui-weave

    Malware was discovered in the npm package ui-weave, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2236. containedcritical

    Malware in transacts

    The npm package transacts was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.

    npmCompromised package
  2237. containedcritical

    Malware in buffer-utilities

    Malware was discovered in the npm package buffer-utilities, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a clean system.

    npmCompromised package
  2238. containedcritical

    Malware in @doaction/eventemitter

    Malware was discovered in the npm package @doaction/eventemitter. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2239. activecritical

    Malware in @doaction/example

    The npm package @doaction/example contains malware that grants full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2240. containedcritical

    Malware in @doaction/examples

    Malware was discovered in the npm package @doaction/examples. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2241. containedcritical

    Malware in @doaction/pay

    Malware was discovered in the npm package @doaction/pay. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2242. activecritical

    Malware in @doaction/mapstore

    The npm package @doaction/mapstore contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2243. containedcritical

    Malware in @doaction/systeminformation

    The npm package @doaction/systeminformation contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2244. activecritical

    Malware in @doaction/signalhub

    Malware was discovered in the npm package @doaction/signalhub. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  2245. containedcritical

    Malware in @doaction/rrweb-sdk

    Malware was discovered in the npm package @doaction/rrweb-sdk. Systems with this package installed or running are considered fully compromised and may have given outside entities full control of the computer.

    npmCompromised package
  2246. containedcritical

    Malware in xorma-js

    Malware was discovered in the npm package xorma-js, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  2247. activecritical

    Malware in @doaction/wasm-loader

    Malware was discovered in the npm package @doaction/wasm-loader. Systems with this package installed or running are considered fully compromised, with potential for complete system takeover.

    npmCompromised package
  2248. activecritical

    Malware in kecak256

    The npm package kecak256 was compromised and contains malware. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2249. activecritical

    Malware in progerss-cli

    Malware discovered in the npm package progerss-cli. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2250. containedcritical

    Malware in enquriers

    The npm package enquriers was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer, and the package should be removed.

    npmCompromised package
  2251. containedcritical

    Malware in cookie-parser-legacy

    Malware was discovered in the npm package cookie-parser-legacy. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2252. containedcritical

    Malware in moustick

    Malware was discovered in the npm package moustick, resulting in full system compromise for any installation. The package should be removed immediately and all secrets and keys rotated from a different computer.

    npmCompromised package
  2253. containedcritical

    Malware in dbmux

    Malware was discovered in the npm package dbmux. Any computer with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different system.

    npmCompromised package
  2254. containedcritical

    Malware in github-archiver

    The npm package github-archiver was found to contain malware. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2255. containedhigh

    New Shai-Hulud attack trojanizes 19 science-focused PyPI packages

    Hackers compromised 19 science-focused packages on PyPI in a Shai-Hulud supply-chain attack. The trojanized packages were collectively downloaded hundreds of thousands of times and delivered malware designed to steal developer secrets.

    Shai-HuludPyPICompromised package
  2256. activecritical

    Malware in chai-mocks

    Malware discovered in the npm package chai-mocks. Systems with this package installed are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  2257. activecritical

    Malware in nodemon-lint

    The npm package nodemon-lint contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2258. activecritical

    Malware in regexp-ts

    The npm package regexp-ts contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  2259. activecritical

    The Hades Campaign: Graph ML PyPI Packages Deploy Cross-Platform Memory Scrapers, AI Analyst Misdirection, and a Wiper Deterrent

    On June 8, 2026, multiple Graph ML PyPI packages were compromised in the Hades campaign, deploying cross-platform memory scrapers, AI prompt injections for analyst misdirection, and token-revocation wipers. The attack targeted the bioinformatics ecosystem with sophisticated evasion techniques.

    HadesPyPICompromised package
  2260. containedcritical

    Malware in nodemon-copack

    The npm package nodemon-copack contained malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  2261. containedcritical

    Malware in classwind-utils

    Malware was discovered in the npm package classwind-utils. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  2262. activehigh

    New IronWorm malware hits 36 packages in npm supply-chain attack

    A supply-chain attack infected 36 packages on npm with IronWorm infostealer malware. The attack compromised multiple packages in the Node Package Manager ecosystem, potentially affecting downstream users and applications.

    IronWormnpmCompromised package
  2263. containedhigh

    Hola Browser for Windows compromised to deliver cryptominer

    The Windows version of Hola Browser was compromised in a supply chain attack that delivered an undeclared cryptocurrency miner executable to users. The compromise affected the browser's distribution or update mechanism.

    OtherCompromised packageUpdate-server compromise
  2264. activecritical

    Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp

    A self-replicating worm named Miasma is spreading across the npm registry by injecting malicious code into binding.gyp files, which execute during npm install without requiring package.json script modifications. The attack has already compromised dozens of packages across multiple maintainer accounts and evades conventional security detection.

    MiasmanpmCompromised packageMalicious commit
  2265. containedcritical

    Multiple redhat-cloud-services npm Packages compromised

    Multiple npm packages in the @redhat-cloud-services scope were compromised with malicious payloads. The attack used preinstall hooks to execute a multi-stage credential harvester targeting cloud and CI/CD platform secrets.

    MiasmanpmCompromised package
  2266. activehigh

    Miasma: Supply Chain Attack Targeting RedHat npm Packages

    Miasma is a supply chain attack targeting RedHat npm packages, leveraging malicious npm packages based on the open-sourced Mini Shai-Hulud malware. Specific affected packages and versions were not disclosed in the available source text.

    Mini Shai HuludnpmCompromised package
  2267. containedcritical

    Microsoft's durabletask PyPI Package Compromised in Supply Chain Attack

    Three malicious versions of Microsoft's durabletask Python package were published to PyPI on May 19, 2026, containing a 28 KB payload that steals credentials from cloud providers (AWS, Azure, GCP), Kubernetes, password managers, and developer tools. The attack has been attributed to the TeamPCP threat group and exhibits indicators of Eastern European cybercrime operations.

    TeamPCPPyPICompromised package
  2268. activecritical

    Active Supply Chain Attack: Malicious node-ipc Versions Published to npm

    StepSecurity identified multiple malicious releases of the popular node-ipc npm package containing an obfuscated payload designed to steal cloud credentials, SSH keys, and CI/CD secrets. The attack is ongoing and under active analysis.

    npmCompromised package
  2269. activecritical

    The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave

    TeamPCP conducted a multi-ecosystem supply chain compromise targeting the @antv package and associated development infrastructure. The attack leveraged GitHub, NPM, and VSCode to steal credentials and establish persistence mechanisms.

    TeamPCPnpmOtherAccount takeoverCompromised packageMalicious maintainer
  2270. activecritical

    Shai-Hulud: Here We Go Again. Mass npm Supply Chain Attack Hits the AntV Ecosystem

    A new wave of the Mini Shai-Hulud worm has compromised multiple npm packages across Alibaba's AntV data visualization ecosystem, including echarts-for-react and timeago.js. Stolen CI/CD secrets are being exfiltrated and dumped to thousands of public GitHub repositories as the attack spreads.

    Mini Shai HuludnpmOtherCompromised packageAccount takeover
  2271. resolvedhigh

    durabletask: TeamPCP's Latest PyPi Compromise

    Malicious versions of the PyPI package durabletask were published, attributed to the TeamPCP threat actor. The attack matches known TeamPCP tactics used in prior supply chain compromises.

    TeamPCPPyPICompromised package
  2272. activehigh

    Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised

    A supply chain campaign called "Mini Shai-Hulud" has compromised multiple npm packages, including high-value TanStack developer tooling. The campaign appears to be an ongoing effort targeting critical npm infrastructure.

    Mini Shai HuludnpmCompromised package
  2273. activecritical

    TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages

    The Mini Shai-Hulud worm is actively compromising legitimate npm packages by hijacking CI/CD pipelines and stealing developer secrets. The attack was first detected by StepSecurity in official @tanstack packages and is spreading across the npm ecosystem in real time.

    TeamPCPMini Shai HuludnpmOtherCompromised packageBuild-system compromise
  2274. containedcritical

    TeamPCP Injects Two-Stage Credential Stealer into xinference PyPI Package

    The xinference package on PyPI was compromised with a two-stage credential stealer attributed to the TeamPCP threat actor. The malicious code was injected into the package, potentially affecting users who installed compromised versions.

    TeamPCPPyPICompromised packageMalicious maintainer
  2275. activecritical

    Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked — 361,000 Weekly Downloads, AWS, GCP, and Azure Credentials Now in Scope

    The Shai-Hulud worm has hijacked intercom-client@7.0.4 (361,510 weekly downloads) via a compromised GitHub Actions OIDC publishing pipeline, 29 hours after compromising mbt@1.2.48 and @cap-js/sqlite@2.2.2. The worm is actively propagating through CI/CD infrastructure stolen from earlier victims, targeting multi-cloud credentials (AWS, GCP, Azure).

    Shai-HuludnpmOtherCompromised packageBuild-system compromiseAccount takeover
  2276. activehigh

    A Mini Shai-Hulud Has Appeared: Obfuscated Bun Runtime Payloads Hit SAP-Related npm Packages

    StepSecurity identified an npm supply chain attack campaign targeting SAP-ecosystem packages using preinstall hooks to download and execute an obfuscated Bun runtime payload. At least two SAP-related npm packages have been confirmed compromised in this active campaign.

    Mini Shai HuludnpmCompromised package
  2277. containedcritical

    Bitwarden CLI Hijacked on npm: Bun-Staged Credential Stealer Targets Developers, GitHub Actions, and AI Tools

    @bitwarden/cli@2026.4.0 was compromised on npm with a malicious preinstall hook that deployed an obfuscated credential stealer. The malware harvests developer secrets, GitHub Actions tokens, and AI tool configurations, exfiltrating encrypted data to a Checkmarx-impersonating domain.

    Shai-HuludTeamPCPnpmCompromised package
  2278. containedhigh

    lightning: Obfuscated JavaScript Credential Stealer Bundled in PyPI Wheel

    The lightning PyPI package versions 2.6.2 and 2.6.3 were compromised on April 30, 2026, containing obfuscated JavaScript code designed to steal credentials. The project's GitHub account showed signs of compromise, with suspicious responses closing vulnerability reports.

    Mini Shai HuludPyPICompromised packageMalicious maintainer
  2279. activehigh

    Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware

    A supply chain campaign dubbed "Mini Shai Hulud" targeted SAP npm packages with malicious versions containing credential-stealing malware. The campaign follows patterns similar to previous Shai-Hulud attacks.

    Mini Shai HuludShai-HuludnpmCompromised packageMalicious commit
  2280. activecritical

    @velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via launchctl Persistence

    A malicious version of the @velora-dex/sdk npm package was published, delivering an architecture-aware macOS backdoor that activates on import with no visible indicators. The attack occurred at the registry level without repository commits or install hooks.

    npmCompromised package
  2281. activecritical

    axios Compromised on npm - Malicious Versions Drop Remote Access Trojan

    A maintainer account for the widely-used axios npm package was compromised and used to publish poisoned versions 1.14.1 and 0.30.4. The malicious releases contained a hidden dependency that drops a cross-platform remote access trojan (RAT).

    UNC1069npmAccount takeoverCompromised package
  2282. containedhigh

    10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions

    TeamPCP compromised 76 Trivy version tags on GitHub Actions in an overnight attack, followed by a similar KICS compromise using the same methodology. The attacks targeted credential exfiltration through malicious GitHub Actions.

    TeamPCPOtherContainer registryCompromised packageAccount takeover
  2283. resolvedcritical

    Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest npm Supply Chain Attack

    StepSecurity detected a compromise of axios, described as the largest npm supply chain attack on a single package by download count. A state-sponsored threat actor is reported to have actively suppressed warnings by deleting GitHub issues. Detection occurred before public disclosure.

    UNC1069npmCompromised packageMalicious maintainer
  2284. containedhigh

    Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw

    Version 2.3.0 of the npm package cline was found to silently install OpenClaw, a malicious payload. The attack was detected and the incident is contained.

    npmCompromised package
  2285. activecritical

    Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor

    Three IoliteLabs VSCode extensions (solidity-macos, solidity-windows, solidity-linux) containing obfuscated backdoors targeting Solidity and Web3 developers across Windows, macOS, and Linux. The backdoors download remote payloads and establish persistence mechanisms on infected systems.

    Container registryOtherCompromised packageMalicious maintainer
  2286. containedcritical

    TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package

    On March 27, 2026, TeamPCP injected a WAV steganography-based credential stealer into two releases of the telnyx Python SDK on PyPI. The group was identified by shared cryptographic signatures and exfiltration methods matching their earlier litellm compromise.

    TeamPCPPyPICompromised package
  2287. containedcritical

    litellm: Credential Stealer Hidden in PyPI Wheel

    A critical supply chain compromise in litellm==1.82.8 on PyPI was identified on March 24, 2026. The malicious PyPI wheel contains a credential stealer hidden in a litellm_init.pth file that executes during package initialization.

    TeamPCPPyPICompromised package
  2288. containedcritical

    Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack

    On March 19, 2026, threat actors attributed to "TeamPCP" injected credential-stealing malware into Aqua Security's Trivy scanner and related GitHub Actions. The compromise affected the supply chain of a widely-used container security tool, potentially exposing credentials and secrets in CI/CD environments.

    TeamPCPContainer registryOtherCompromised packageMalicious commit
  2289. containedcritical

    bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys

    bittensor-wallet 4.0.2 was published to PyPI on March 17, 2026 with a backdoor that exfiltrates private keys. The compromised package remained available for approximately 48 hours before being yanked from the repository.

    PyPICompromised package
  2290. containedhigh

    Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Downloads Compromised

    Malicious releases were discovered in two popular React Native npm packages—react-native-international-phone-number and react-native-country-select—affecting packages with 130K+ monthly downloads combined. StepSecurity detected and reported the compromise on March 16, 2026, and immediately notified maintainers and the community.

    ForceMemonpmCompromised package
  2291. activecritical

    Malware in ulid-os

    Malware in ulid-os Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside en

    npmCompromised package
  2292. activecritical

    Malware in utils-mf

    Malware in utils-mf Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside e

    npmCompromised package
  2293. activecritical

    Malware in react-ui-polyfills

    Malware in react-ui-polyfills Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an

    npmCompromised package
  2294. activecritical

    Malware in glyphr

    Malware in glyphr Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside ent

    npmCompromised package
  2295. activecritical

    Malware in reactvora

    Malware in reactvora Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside

    npmCompromised package
  2296. activecritical

    Malware in @jagreehal/workflow

    Malware in @jagreehal/workflow Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to a

    MiasmanpmCompromised package
  2297. activecritical

    Malware in autotel-terminal

    Malware in autotel-terminal Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an o

    MiasmanpmCompromised package
  2298. activecritical

    Withdrawn Advisory: Malware in supabase

    Withdrawn Advisory: Malware in supabase ### Withdrawn Advisory This advisory has been withdrawn because the malware detection was a false positive. This link is maintained to preserve external references. ### Original Description Any computer that has this package installed or running should be considered fully comprom

    npmCompromised package
  2299. activecritical

    Malware in nodemon-pack

    Malware in nodemon-pack Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsi

    npmCompromised package
  2300. activecritical

    Malware in webpack-json

    Malware in webpack-json Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsi

    npmCompromised package
  2301. activecritical

    Malware in nodemon-webpatch

    Malware in nodemon-webpatch Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an o

    npmCompromised package
  2302. activecritical

    Malware in chai-midpatch

    Malware in chai-midpatch Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outs

    npmCompromised package
  2303. activecritical

    Malware in chai-parse

    Malware in chai-parse Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside

    npmCompromised package
  2304. activecritical

    Malware in @redhat-cloud-services/frontend-components-testing

    Malware in @redhat-cloud-services/frontend-components-testing Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the co

    MiasmanpmCompromised package
  2305. activecritical

    Malware in @ewfewfewf/testhackerrr

    Malware in @ewfewfewf/testhackerrr Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given

    npmCompromised package
  2306. activecritical

    Malware in @osamdefeirrighs/testhackfrrferrr

    Malware in @osamdefeirrighs/testhackfrrferrr Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have b

    npmCompromised package
  2307. activecritical

    Malware in @pcldpvkoewpogw/testhacker

    Malware in @pcldpvkoewpogw/testhacker Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been giv

    npmCompromised package
  2308. activecritical

    Malware in to-cms

    Malware in to-cms Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside ent

    npmCompromised package
  2309. activecritical

    Malware in chainix

    Malware in chainix Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside en

    npmCompromised package
  2310. activecritical

    Malware in chai-as-minted

    Malware in chai-as-minted Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an out

    npmCompromised package
  2311. activecritical

    Malware in @tmecontinue/cli

    Malware in @tmecontinue/cli Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an o

    npmCompromised package
  2312. activecritical

    Malware in collected-forms-embed-js

    Malware in collected-forms-embed-js Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given

    npmCompromised package
  2313. activecritical

    Malware in cms-github

    Malware in cms-github Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside

    npmCompromised package
  2314. activecritical

    Malware in cms-storehub

    Malware in cms-storehub Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsi

    npmCompromised package
  2315. activecritical

    Malware in shopifyto-cms

    Malware in shopifyto-cms Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outs

    npmCompromised package
  2316. activecritical

    Malware in @antoncallahan/aws-user-helper

    Malware in @antoncallahan/aws-user-helper Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    npmCompromised package
  2317. activecritical

    Malware in json-to-simple-graphql-schema

    Malware in json-to-simple-graphql-schema Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    npmCompromised package
  2318. activecritical

    Malware in @redhat-cloud-services/entitlements-client

    Malware in @redhat-cloud-services/entitlements-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m

    MiasmanpmCompromised package
  2319. activecritical

    Malware in @chat-template/auth

    Malware in @chat-template/auth Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to a

    npmCompromised package
  2320. activecritical

    Malware in cms-helpgit

    Malware in cms-helpgit Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsid

    npmCompromised package
  2321. activecritical

    Malware in @redhat-cloud-services/sources-client

    Malware in @redhat-cloud-services/sources-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may ha

    MiasmanpmCompromised package
  2322. activecritical

    Malware in @redhat-cloud-services/frontend-components-remediations

    Malware in @redhat-cloud-services/frontend-components-remediations Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of t

    MiasmanpmCompromised package
  2323. activecritical

    Malware in peertube-plugin-google-analytics-js

    Malware in peertube-plugin-google-analytics-js Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  2324. activecritical

    Malware in @redhat-cloud-services/rbac-client

    Malware in @redhat-cloud-services/rbac-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    MiasmanpmCompromised package
  2325. activecritical

    Malware in @redhat-cloud-services/topological-inventory-client

    Malware in @redhat-cloud-services/topological-inventory-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the c

    MiasmanpmCompromised package
  2326. activecritical

    Malware in @tmecontinue/claude

    Malware in @tmecontinue/claude Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to a

    npmAI agents & skillsCompromised package
  2327. activecritical

    Malware in xarc-webpack-cli

    Malware in xarc-webpack-cli Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an o

    npmCompromised package
  2328. activecritical

    Malware in @redhat-cloud-services/quickstarts-client

    Malware in @redhat-cloud-services/quickstarts-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer ma

    MiasmanpmCompromised package
  2329. activecritical

    Malware in @redhat-cloud-services/integrations-client

    Malware in @redhat-cloud-services/integrations-client Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m

    MiasmanpmCompromised package
  2330. activecritical

    Malware in randomlogs

    Malware in randomlogs Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside

    npmCompromised package
  2331. activecritical

    Malware in @redhat-cloud-services/frontend-components-config

    Malware in @redhat-cloud-services/frontend-components-config Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the com

    MiasmanpmCompromised package
  2332. activecritical

    Malware in loading-session

    Malware in loading-session Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an ou

    npmCompromised package
  2333. activecritical

    Malware in motion-tool

    Malware in motion-tool Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsid

    npmCompromised package
  2334. activecritical

    Malware in jingmeideshishi

    Malware in jingmeideshishi Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an ou

    npmCompromised package
  2335. activecritical

    Malware in @redhat-cloud-services/eslint-config-redhat-cloud-services

    Malware in @redhat-cloud-services/eslint-config-redhat-cloud-services Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control o

    MiasmanpmCompromised package
  2336. activecritical

    Malware in @redhat-cloud-services/types

    Malware in @redhat-cloud-services/types Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been g

    MiasmanpmCompromised package
  2337. activecritical

    Malware in @redhat-cloud-services/frontend-components

    Malware in @redhat-cloud-services/frontend-components Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m

    MiasmanpmCompromised package
  2338. activecritical

    Malware in nemo-reporter

    Malware in nemo-reporter Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outs

    npmCompromised package
  2339. activecritical

    Malware in @redhat-cloud-services/rule-components

    Malware in @redhat-cloud-services/rule-components Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may h

    MiasmanpmCompromised package
  2340. activecritical

    Malware in audit-logsss

    Malware in audit-logsss Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outsi

    npmCompromised package
  2341. activecritical

    Malware in @redhat-cloud-services/hcc-feo-mcp

    Malware in @redhat-cloud-services/hcc-feo-mcp Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    MiasmanpmAI agents & skillsCompromised package
  2342. activecritical

    Malware in @redhat-cloud-services/frontend-components-config-utilities

    Malware in @redhat-cloud-services/frontend-components-config-utilities Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control

    MiasmanpmCompromised package
  2343. activecritical

    Malware in @redhat-cloud-services/chrome

    Malware in @redhat-cloud-services/chrome Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    MiasmanpmCompromised package
  2344. activecritical

    Malware in @t-in-one/add_application_tid

    Malware in @t-in-one/add_application_tid Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    npmCompromised package
  2345. activecritical

    Malware in @t-in-one/get_application_hid

    Malware in @t-in-one/get_application_hid Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    npmCompromised package
  2346. activecritical

    Malware in @t-in-one/add_application

    Malware in @t-in-one/add_application Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been give

    npmCompromised package
  2347. activecritical

    Malware in @cloudplatform-single-spa/ml-ai-agents-agent-system

    Malware in @cloudplatform-single-spa/ml-ai-agents-agent-system Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the c

    npmCompromised package
  2348. activecritical

    Malware in @cloudplatform-single-spa/security-groups

    Malware in @cloudplatform-single-spa/security-groups Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer ma

    npmCompromised package
  2349. activecritical

    Withdrawn Advisory: Malware in puppeteer

    Withdrawn Advisory: Malware in puppeteer ### Withdrawn Advisory This advisory has been withdrawn because the malicious package detection was a false positive. This link is maintained to preserve external references. ### Original Description Any computer that has this package installed or running should be considered fu

    npmCompromised package
  2350. activecritical

    Malware in @cloudplatform-single-spa/floating-ips

    Malware in @cloudplatform-single-spa/floating-ips Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may h

    npmCompromised package
  2351. activecritical

    Malware in @cloudplatform-single-spa/enterprise

    Malware in @cloudplatform-single-spa/enterprise Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may hav

    npmCompromised package
  2352. activecritical

    Malware in @t-in-one/prefill_bundle_data_token

    Malware in @t-in-one/prefill_bundle_data_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  2353. activecritical

    Malware in @cloudplatform-single-spa/business-solutions

    Malware in @cloudplatform-single-spa/business-solutions Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer

    npmCompromised package
  2354. activecritical

    Malware in @t-in-one/send_add_application

    Malware in @t-in-one/send_add_application Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    npmCompromised package
  2355. activecritical

    Malware in @t-in-one/prefill_credit_data_token

    Malware in @t-in-one/prefill_credit_data_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  2356. activecritical

    Malware in @t-in-one/only_difference_payload

    Malware in @t-in-one/only_difference_payload Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have b

    npmCompromised package
  2357. activecritical

    Malware in midoss

    Malware in midoss Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside ent

    npmCompromised package
  2358. activecritical

    Malware in @cloudplatform-single-spa/dataplatform-trino

    Malware in @cloudplatform-single-spa/dataplatform-trino Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer

    npmCompromised package
  2359. activecritical

    Malware in @t-in-one/prefill_transformers_data_token

    Malware in @t-in-one/prefill_transformers_data_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer ma

    npmCompromised package
  2360. activecritical

    Malware in @cloudplatform-single-spa/logaas

    Malware in @cloudplatform-single-spa/logaas Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have be

    npmCompromised package
  2361. activecritical

    Malware in @cloudplatform-single-spa/base-static-page

    Malware in @cloudplatform-single-spa/base-static-page Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m

    npmCompromised package
  2362. activecritical

    Malware in @t-in-one/safe_local_storage_token

    Malware in @t-in-one/safe_local_storage_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  2363. activecritical

    Malware in power-platform-playwright-toolkit

    Malware in power-platform-playwright-toolkit Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have b

    npmCompromised package
  2364. activecritical

    Malware in @cloudplatform-single-spa/administration

    Malware in @cloudplatform-single-spa/administration Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may

    npmCompromised package
  2365. activecritical

    Malware in @cloudplatform-single-spa/cnapp-ui

    Malware in @cloudplatform-single-spa/cnapp-ui Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  2366. activecritical

    Malware in @cloudplatform-single-spa/cp-api-gw

    Malware in @cloudplatform-single-spa/cp-api-gw Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  2367. activecritical

    Malware in @cloudplatform-single-spa/dataplatform-metastore

    Malware in @cloudplatform-single-spa/dataplatform-metastore Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the comp

    npmCompromised package
  2368. activecritical

    Malware in @cloudplatform-single-spa/employees

    Malware in @cloudplatform-single-spa/employees Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  2369. activecritical

    Malware in @sber-ecom-core/sberpay-widget

    Malware in @sber-ecom-core/sberpay-widget Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    npmCompromised package
  2370. activecritical

    Malware in customerdigital-service-lib

    Malware in customerdigital-service-lib Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been gi

    npmCompromised package
  2371. activecritical

    Malware in @capibar.chat/ui-kit

    Malware in @capibar.chat/ui-kit Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to

    npmCompromised package
  2372. activecritical

    Malware in @t-in-one/form_product_token

    Malware in @t-in-one/form_product_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been g

    npmCompromised package
  2373. activecritical

    Malware in @t-in-one/application_id_storage_key_token

    Malware in @t-in-one/application_id_storage_key_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer m

    npmCompromised package
  2374. activecritical

    Malware in @cloudplatform-single-spa/ml-ai-agents-agent

    Malware in @cloudplatform-single-spa/ml-ai-agents-agent Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer

    npmCompromised package
  2375. activecritical

    Malware in @cloudplatform-single-spa/svp-baas

    Malware in @cloudplatform-single-spa/svp-baas Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  2376. activecritical

    Malware in @cloudplatform-single-spa/cloud-dns

    Malware in @cloudplatform-single-spa/cloud-dns Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  2377. activecritical

    Malware in @cloudplatform-single-spa/dataplatform

    Malware in @cloudplatform-single-spa/dataplatform Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may h

    npmCompromised package
  2378. activecritical

    Malware in @cloudplatform-single-spa/vpn

    Malware in @cloudplatform-single-spa/vpn Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been

    npmCompromised package
  2379. activecritical

    Malware in @t-in-one/save_application_hid_to_storage

    Malware in @t-in-one/save_application_hid_to_storage Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer ma

    npmCompromised package
  2380. activecritical

    Malware in @t-in-one/restore_application_hid_from_storage

    Malware in @t-in-one/restore_application_hid_from_storage Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the comput

    npmCompromised package
  2381. activecritical

    Malware in @cloudplatform-single-spa/monitoring

    Malware in @cloudplatform-single-spa/monitoring Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may hav

    npmCompromised package
  2382. activecritical

    Malware in @cloudplatform-single-spa/marketplace-gigachat

    Malware in @cloudplatform-single-spa/marketplace-gigachat Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the comput

    npmCompromised package
  2383. activecritical

    Malware in @cloudplatform-single-spa/svp-s3-storage

    Malware in @cloudplatform-single-spa/svp-s3-storage Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may

    npmCompromised package
  2384. activecritical

    Malware in @t-in-one/add_application_service_token

    Malware in @t-in-one/add_application_service_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may

    npmCompromised package
  2385. activecritical

    Malware in @cloudplatform-single-spa/ssh-keys

    Malware in @cloudplatform-single-spa/ssh-keys Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  2386. activecritical

    Malware in @cloudplatform-single-spa/support

    Malware in @cloudplatform-single-spa/support Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have b

    npmCompromised package
  2387. activecritical

    Malware in @cloudplatform-single-spa/arenadata-db

    Malware in @cloudplatform-single-spa/arenadata-db Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may h

    npmCompromised package
  2388. activecritical

    Malware in @t-in-one/add_app_middleware_token

    Malware in @t-in-one/add_app_middleware_token Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package
  2389. activecritical

    Malware in @cloudplatform-single-spa/svp-interfaces

    Malware in @cloudplatform-single-spa/svp-interfaces Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may

    npmCompromised package
  2390. activecritical

    Malware in @cloudplatform-single-spa/datagrid

    Malware in @cloudplatform-single-spa/datagrid Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have

    npmCompromised package