Supply Chain Incidents

Malicious packages, backdoors, typosquats, and dependency confusion attacks

20
Total Incidents

github.com/BufferZoneCorp/config-loader

Go

MAL-2026-3620

Malicious code in github.com/BufferZoneCorp/config-loader (Go)

Malware
May 2026

github.com/BufferZoneCorp/grpc-client

Go

MAL-2026-3627

Malicious code in github.com/BufferZoneCorp/grpc-client (Go)

Malware
May 2026

github.com/BufferZoneCorp/log-core

Go

MAL-2026-3628

Malicious code in github.com/BufferZoneCorp/log-core (Go)

Malware
May 2026

github.com/BufferZoneCorp/go-stdlib-ext

Go

MAL-2026-3624

Malicious code in github.com/BufferZoneCorp/go-stdlib-ext (Go)

Malware
May 2026

github.com/BufferZoneCorp/go-weather-sdk

Go

MAL-2026-3626

Malicious code in github.com/BufferZoneCorp/go-weather-sdk (Go)

Malware
May 2026

github.com/BufferZoneCorp/go-envconfig

Go

MAL-2026-3621

Malicious code in github.com/BufferZoneCorp/go-envconfig (Go)

Malware
May 2026

github.com/BufferZoneCorp/go-metrics-sdk

Go

MAL-2026-3622

Malicious code in github.com/BufferZoneCorp/go-metrics-sdk (Go)

Malware
May 2026

github.com/BufferZoneCorp/net-helper

Go

MAL-2026-3629

Malicious code in github.com/BufferZoneCorp/net-helper (Go)

Malware
May 2026

github.com/BufferZoneCorp/go-retryablehttp

Go

MAL-2026-3623

Malicious code in github.com/BufferZoneCorp/go-retryablehttp (Go)

Malware
May 2026

github.com/BufferZoneCorp/go-stdlog

Go

MAL-2026-3625

Malicious code in github.com/BufferZoneCorp/go-stdlog (Go)

Malware
May 2026

github.com/zarf-dev/zarf

Go

GHSA-pj97-4p9w-gx3q

Zarf has a Path Traversal via Malicious Package Metadata.Name โ€” Arbitrary File Write

Malware
1 CVE
Apr 2026

github.com/esm-dev/esm.sh

Go

GHSA-2657-3c98-63jq

esm.sh has a path traversal in extractPackageTarball enables file writes from malicious packages

Malware
1 CVE
Jan 2026

github.com/ornatedoctrin/layout

Go

MAL-2025-2546

Malicious code in github.com/ornatedoctrin/layout (Go)

Typosquat
Mar 2025

github.com/shallowmulti/hypert

Go

MAL-2025-2548

Malicious code in github.com/shallowmulti/hypert (Go)

Typosquat
Mar 2025

github.com/vainreboot/layout

Go

MAL-2025-2551

Malicious code in github.com/vainreboot/layout (Go)

Typosquat
Mar 2025

github.com/shadowybulk/hypert

Go

MAL-2025-2547

Malicious code in github.com/shadowybulk/hypert (Go)

Typosquat
Mar 2025

github.com/thankfulmai/hypert

Go

MAL-2025-2549

Malicious code in github.com/thankfulmai/hypert (Go)

Typosquat
Mar 2025

github.com/utilizedsun/layout

Go

MAL-2025-2550

Malicious code in github.com/utilizedsun/layout (Go)

Typosquat
Mar 2025

github.com/belatedplanet/hypert

Go

MAL-2025-2544

Malicious code in github.com/belatedplanet/hypert (Go)

Typosquat
Mar 2025

github.com/boltdb-go/bolt

Go

MAL-2025-2545

Malicious code in github.com/boltdb-go/bolt (Go)

Typosquat
Mar 2025
Showing 1 - 20 of 20
Agentic AI ยท Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains โ€” not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001