Skip to content
supplychainattack.orgSupply chain attack incident catalog

Dependency confusion incidents

49 confirmed incidents involving the dependency-confusion technique.

  1. containedcritical

    Malicious code in @noobaihome/amis-simple-area-widget (npm)

    @noobaihome/amis-simple-area-widget@1.0.0 on npm contains malicious code in a preinstall hook that performs blind SSRF/network reconnaissance, fetching internal Baidu network content and exfiltrating it to an attacker-controlled IP. The package is a dependency-confusion lure targeting an internal @noobaihome scope.

    npmCompromised packageDependency confusion
  2. resolvedcritical

    Malicious code in neutrl-contracts (PyPI)

    The PyPI package neutrl-contracts intentionally depends on a malicious package (neutrl-core) that exfiltrates sensitive credentials including environment variables, SSH keys, and dotenv files. The malicious code is disguised as telemetry and activated remotely by an attacker-controlled endpoint.

    PyPICompromised packageDependency confusion
  3. containedcritical

    Malicious code in plp-contract (PyPI)

    The PyPI package plp-contract intentionally depends on a malicious package (neutrl-core) designed to exfiltrate sensitive credentials including environment variables, SSH keys, and dotenv files. The malicious code is disguised as telemetry and activates via remote command delivery from an attacker-controlled endpoint.

    2026 08 Neutrl CorePyPICompromised packageDependency confusion
  4. resolvedcritical

    Malicious code in chai-tracker (npm)

    chai-tracker, a malicious npm package impersonating chai-spies, executes arbitrary code from an attacker-controlled dependency (dbconnectify) at plugin load time. The malicious code is disguised within the chai plugin initialization and runs in a detached child process with suppressed output.

    npmCompromised packageDependency confusion
  5. resolvedhigh

    Malicious code in cubesat-upstream-driver (PyPI)

    Malicious code was published to PyPI in the cubesat-upstream-driver package, capable of collecting environment variables. The package was detected as part of a CTF-like exercise or pentest campaign and does not appear to exfiltrate data autonomously.

    PyPICompromised packageDependency confusion
  6. resolvedcritical

    Malicious code in sme-rko-finance-front-operations-notifications-impl (npm)

    The npm package sme-rko-finance-front-operations-notifications-impl contained malicious code that executed platform-specific payloads fetched from attacker-controlled infrastructure upon installation. The package used obfuscation and dependency-confusion tactics to evade detection and mimic internal naming conventions.

    npmCompromised packageDependency confusion
  7. resolvedcritical

    Malicious code in titan-exchange-shared-permissions (npm)

    titan-exchange-shared-permissions@99.9.9 on npm is a dependency-confusion reconnaissance package that executes a postinstall script to collect and exfiltrate system information (username, hostname, working directory, IPv4 address) to a remote webhook endpoint.

    npmDependency confusionTyposquatting
  8. containedcritical

    Malicious code in sme-rko-finance-front-payments-currency-payment-domain (npm)

    A malicious npm package named sme-rko-finance-front-payments-currency-payment-domain was published publicly, designed to mimic an internal corporate package name (dependency-confusion attack). On installation or import, the package executes arbitrary native code via multiple obfuscated loader mechanisms, establishing command-and-control communication through DNS TXT records and Cloudflare Workers.

    npmCompromised packageDependency confusion
  9. containedcritical

    Malicious code in @depup/memfs (npm)

    @depup/memfs is a malicious republish of the legitimate memfs package that strips upstream source code and injects nine attacker-controlled @jsonjoy.com/fs-* dependencies. Installing the package automatically executes code from these injected dependencies without requiring lifecycle hooks.

    npmCompromised packageDependency confusion
  10. resolvedcritical

    Malicious code in pilgrimage-portal-client (npm)

    pilgrimage-portal-client version 99.0.0 on npm contained malicious code in a postinstall hook that exfiltrated the installer's hostname, timestamp, and package metadata to an attacker-controlled IP endpoint (http://134.119.222.10:9009/canary) over plain HTTP without user consent.

    npmCompromised packageDependency confusion
  11. activecritical

    Malicious code in electrode-ota-ui-app (npm)

    Malicious npm package electrode-ota-ui-app version 99.0.1 exploits dependency confusion to target the electrode-io internal package name. The package executes a postinstall script that collects host identifiers, public IP, and geolocation data, then exfiltrates it to a Burp Collaborator endpoint controlled by the attacker.

    npmDependency confusionCompromised package
  12. resolvedcritical

    Malicious code in wos-library-ui (npm)

    wos-library-ui@99.0.0 on npm contained malicious code that executed a preinstall script to exfiltrate system information (hostname, username, working directory) via DNS and HTTP to an attacker-controlled Interactsh subdomain. The package exploited dependency confusion by using an inflated version number to target internal Inditex packages.

    npmDependency confusionCompromised package
  13. resolvedcritical

    Malicious code in commonweb-balance (npm)

    commonweb-balance@99.9.1 is a malicious npm package that serves as a lure to pull an out-of-registry dependency (ltidisafe) from a mutable Google Cloud Storage bucket, bypassing npm registry review. The package contains no legitimate functionality and was designed to inject untrusted code into the dependency tree.

    npmCompromised packageDependency confusion
  14. containedcritical

    Malicious code in connect-contingency (npm)

    connect-contingency@99.9.1 is a malicious npm package that uses dependency confusion tactics to pull attacker-controlled code from an external Google Cloud Storage bucket. The package is a hollow stub with an inflated version number and declares a direct tarball dependency on ltidisafe, which is downloaded and executed during installation outside npm registry integrity controls.

    npmDependency confusionCompromised package
  15. containedcritical

    Malicious code in aitable-workflow-server (npm)

    Malicious code was published in aitable-workflow-server (npm) version 9.9.9. The package contains OS command execution and outbound HTTP POST requests for host reconnaissance and data beaconing, with no legitimate workflow-server functionality.

    npmCompromised packageDependency confusion
  16. resolvedcritical

    Malicious code in dbk-ui-forms (npm)

    The npm package dbk-ui-forms version 99.0.1 contained malicious code that executed during installation, collecting sensitive host and environment information and exfiltrating it to an attacker-controlled domain. The package appears to be a dependency-confusion attack targeting internal build systems.

    npmCompromised packageDependency confusion
  17. resolvedcritical

    Malicious code in lib-frontsga (npm)

    Malicious npm package 'lib-frontsga' version 9.999.999 exploits dependency confusion to target organizations with an internal package of the same name. A preinstall/postinstall script collects host and CI environment identifiers and exfiltrates them via DNS and HTTP callbacks to an attacker-controlled domain.

    npmCompromised packageDependency confusion
  18. containedcritical

    Malicious code in cewe-npm-cops (npm)

    cewe-npm-cops@99.9.9 is a malicious npm package that exfiltrates the installer's machine hostname via DNS to an attacker-controlled out-of-band service. The package uses a high version number (99.9.9) to override internal packages during dependency resolution and executes a preinstall script that leaks system information.

    npmCompromised packageDependency confusion
  19. resolvedcritical

    Malicious code in dpdgroup-css (npm)

    The npm package dpdgroup-css contained malicious code that executed on installation, exfiltrating the installer's hostname to an external IP address. The package name mimics an internal DPDgroup scope, suggesting a dependency-confusion attack targeting the courier organization.

    npmCompromised packageDependency confusion
  20. containedcritical

    Malicious code in commonweb-flow (npm)

    Malicious npm package commonweb-flow published with versions 7.999.999 and 10.11.0 containing code that fetches and executes arbitrary code from an external server (artifacts.yosiroute.com) during npm install. The package exhibits dependency-confusion characteristics with inflated version numbers and placeholder metadata.

    npmCompromised packageDependency confusion
  21. resolvedcritical

    Malicious code in dojo-rn-interview (npm)

    dojo-rn-interview@1.0.1 on npm contains malicious code that executes a preinstall script to collect host identifiers and system files, then exfiltrates the data to a Burp Collaborator domain. The package appears designed as a dependency-confusion reconnaissance beacon targeting internal build systems.

    npmCompromised packageDependency confusion
  22. resolvedcritical

    Malicious code in @catamania/front-components (npm)

    The npm package @catamania/front-components contained malicious code in postinstall.js that performed host reconnaissance and exfiltrated system information to a webhook.site URL. The package appears to be a dependency-confusion probe or reconnaissance attack, with the legitimate index.js containing only a trivial Vue button component.

    npmCompromised packageDependency confusion
  23. resolvedcritical

    Malicious code in @depup/nuxt (npm)

    @depup/nuxt on npm was compromised with malicious code that injects a hidden dependency on a lookalike package (@dxup/nuxt) and tampers the build output to auto-load it as a privileged Nuxt module, executing arbitrary code in the build/dev context.

    npmCompromised packageDependency confusion
  24. resolvedhigh

    Malicious code in atlas-internal (PyPI)

    Multiple malicious versions of atlas-internal were published to PyPI containing code that exfiltrates host information (hostname, working directory, username) during installation. The package overrides the egg_info command in setup.py to execute automatically on pip install without user interaction, sending collected data to attacker-controlled out-of-band callback servers.

    PyPICompromised packageDependency confusion
  25. containedcritical

    Malicious code in @depup/astro (npm)

    @depup/astro is a malicious npm package that impersonates the legitimate Astro framework by spoofing author and repository metadata, while systematically replacing well-known dependencies with lookalike packages under different maintainers. The package source code was rewritten to import from these lookalike packages, causing normal npm installs to execute attacker-controlled code instead of legitimate upstream dependencies.

    npmTyposquattingDependency confusionCompromised package
  26. resolvedcritical

    Malicious code in content-common (npm)

    Malicious code was published in content-common@99.9.9 on npm. The package contained a preinstall script that executed arbitrary code via HTTP GET to an attacker-controlled Burp Suite Collaborator endpoint, leaking installer IP and DNS metadata. The version number suggests a dependency-confusion probe against an internal package.

    npmCompromised packageDependency confusion
  27. resolvedcritical

    Malicious code in @wbnr/frontend-shared (npm)

    The npm package @wbnr/frontend-shared contained malicious code in a preinstall lifecycle script that exfiltrated installer system information (username, hostname) to a third-party callback domain via DNS and HTTPS, consistent with a dependency-confusion probe.

    npmCompromised packageDependency confusion
  28. resolvedcritical

    Malicious code in cdf-tag-commander-helper (npm)

    The npm package cdf-tag-commander-helper@3.6.2 contained malicious code in its preinstall script that executed reconnaissance on the host system. On installation, the script ran whoami and hostname commands, retrieved the machine's public IP, and sent this information to an attacker-controlled out-of-band callback domain, consistent with dependency-confusion targeting.

    npmDependency confusion
  29. resolvedcritical

    Malicious code in @united-airlines-org/atmos-design-system (npm)

    The npm package @united-airlines-org/atmos-design-system contains a malicious preinstall script that exfiltrates host reconnaissance data (hostname, directory listing, username) to an attacker-controlled endpoint. The package uses a scope name resembling an internal United Airlines organization, matching a dependency-confusion attack pattern.

    npmCompromised packageDependency confusion
  30. resolvedcritical

    Malicious code in consumerweb-creditcollection (npm)

    consumerweb-creditcollection@99.9.1 is a malicious npm package that uses dependency confusion to force installation of attacker-controlled code from a Google Cloud Storage bucket. The package exports an empty object but pulls in a dependency (ltidisafe) pinned to an arbitrary tarball URL outside the npm registry, bypassing security scanning.

    npmDependency confusionCompromised package
  31. resolvedcritical

    Malicious code in tinkoff-statist-browser-typed-client-sme.compliance.web.events (npm)

    The npm package tinkoff-statist-browser-typed-client-sme.compliance.web.events contains malicious code that downloads and executes platform-specific binary payloads on require. The package name mimics an internal Tinkoff namespace to evade detection and uses DNS TXT covert channels as a fallback delivery mechanism.

    npmCompromised packageTyposquattingDependency confusion
  32. containedcritical

    Malicious code in greatcall-customers-commandapi (npm)

    greatcall-customers-commandapi@99.0.0 is a dependency-confusion attack package that executes malicious code during npm install, collecting system information, credentials, and environment variables, then exfiltrating them to a remote webhook.

    npmDependency confusionCompromised package
  33. containedcritical

    Malicious code in data-format-helper (npm)

    The npm package data-format-helper contained malicious code in a postinstall.js script that auto-executes on installation, collecting sensitive environment variables, CI/CD secrets, and cloud credentials, then exfiltrating them to an attacker-controlled domain. The package appears to be a dependency-confusion attack targeting Tencent internal infrastructure.

    npmCompromised packageDependency confusion
  34. resolvedcritical

    Malicious code in fundraiserservpp (npm)

    fundraiserservpp@2.0.0 on npm contained malicious code that executed a preinstall script to exfiltrate host metadata to an attacker-controlled endpoint. The package was designed to confirm successful installation in target build environments as part of a dependency-confusion reconnaissance attack.

    npmDependency confusion
  35. resolvedcritical

    Malicious code in kepler (npm)

    The kepler npm package (version 2.0.999) contains malicious code that injects an off-registry, unverified dependency (flag-serial-object-syntax) from a third-party host (artifacts.yosiroute.com) with install scripts enabled, allowing arbitrary code execution on installation.

    npmCompromised packageDependency confusion
  36. containedcritical

    Malicious code in multi-acct (npm)

    multi-acct@99.99.99 is a malicious npm package that acts as a wrapper to deliver arbitrary code execution. It declares a dependency on vector-cursor-stream-engine that is fetched from an external third-party URL (artifacts.yosiroute.com) with install scripts enabled, allowing remote code execution during npm install.

    npmCompromised packageDependency confusion
  37. containedcritical

    Malicious code in redis-type-xyz (npm)

    redis-type-xyz is a malicious npm package that impersonates Redis OM by copying its metadata while substituting a known-malicious ulid-xyz dependency. Installation triggers a postinstall hook that establishes C2 communication and enables system compromise including persistence and arbitrary code execution.

    npmCompromised packageTyposquattingDependency confusion
  38. containedcritical

    Malicious code in sigchain-js (npm)

    Malicious code was injected into the published npm package sigchain-js, executing arbitrary code on installation via DES-decrypted payloads from companion packages thedata and tchain-api. The attack also involved typosquatting axios to version 1.18.1, which does not exist in legitimate release history.

    npmCompromised packageDependency confusionTyposquatting
  39. containedcritical

    Malicious code in @design-system-coopeuch/web (npm)

    @design-system-coopeuch/web versions 999.0.4 and 999.0.0 on npm contained malicious code implementing a dependency-confusion attack. The package included a preinstall hook that exfiltrated host identifiers (hostname, working directory, user ID, environment variables) to a hardcoded IP address via cleartext HTTP.

    npmDependency confusionCompromised package
  40. resolvedcritical

    Malicious code in @webapp-next/store (npm)

    The npm package @webapp-next/store contained malicious code that executed automatically on installation, collecting system and user information and exfiltrating it to an attacker-controlled server. The package had no legitimate functionality and used a dependency-confusion lure with a scope resembling a legitimate namespace.

    npmCompromised packageDependency confusion
  41. containedcritical

    Malicious code in secdriven (npm)

    The npm package 'secdriven' version 1.0.8 contains malicious postinstall code that exfiltrates host identity, username, working directory, and CI environment variables to a third-party OOB-detection endpoint. The package is a dependency-confusion payload targeting Google's internal namespace, masquerading as a security research canary.

    npmDependency confusionCompromised package
  42. resolvedcritical

    Malicious code in @pelmnaads/naads-common-logger (npm)

    Malicious code in @pelmnaads/naads-common-logger (npm) version 19999.0.1 exploited dependency confusion by publishing to the public npm registry with an abnormally high version number. A preinstall script transmitted installer hostname data to a Burp Collaborator endpoint (h5nvwrz2815ubw84cpkwhezm5db9z1nq.b.mburpcollab.com), silently exfiltrating build host identity.

    npmDependency confusionCompromised package
  43. resolvedcritical

    Malicious code in @convera/ui-shared (npm)

    The npm package @convera/ui-shared version 0.0.2 contained malicious code that exfiltrated system hostname and username during installation via a preinstall script. The package was published under a private namespace scope, creating a dependency-confusion attack surface against the Convera organization.

    npmCompromised packageDependency confusion
  44. resolvedhigh

    Malicious code in affinequant (PyPI)

    The affinequant package on PyPI contained malicious code that exfiltrated basic system information (hostname, path, username) to the package author upon installation or import. The package was part of a broader campaign of malicious packages on PyPI and communicated with a domain associated with malicious activity.

    PyPICompromised packageTyposquattingDependency confusion
  45. resolvedhigh

    Malicious code in adanbu (PyPI)

    The PyPI package 'adanbu' version 92.6 contained malicious code that exfiltrated basic system information (hostname, path, username) to the package author upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages on PyPI.

    PyPICompromised packageTyposquattingDependency confusion
  46. resolvedhigh

    Malicious code in zabitog (PyPI)

    Malicious code was discovered in the zabitog package on PyPI. The package contained obfuscated code designed to exfiltrate basic system data such as hostname, IP address, and username. The incident was identified as part of campaign 2026-02-zabitmajeed00 and attributed to OpenSSF's malicious packages research.

    PyPICompromised packageDependency confusion
  47. containedhigh

    Malicious code in yhaplo1 (PyPI)

    Malicious package yhaplo1 was published to PyPI as a dependency confusion attack. The package contained code to exfiltrate basic system information but did not perform active exfiltration. The attacker identified themselves as a HackerOne user conducting a bug bounty test.

    PyPIDependency confusionCompromised package
  48. resolvedhigh

    Malicious code in adandv (PyPI)

    The adandv package on PyPI contained malicious code designed to exfiltrate basic system information (hostname, path, username) to the package author. The package was part of a broader campaign of malicious pentest-themed packages flooding PyPI.

    PyPICompromised packageTyposquattingDependency confusion
  49. resolvedhigh

    Malicious code in adandu (PyPI)

    The PyPI package 'adandu' was identified as malicious, containing code to exfiltrate basic system information (hostname, path, username) upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages and communicated with domains associated with malicious activity.

    PyPICompromised packageTyposquattingDependency confusion