Supply Chain Incidents

Malicious packages, backdoors, typosquats, and dependency confusion attacks

214,285
Total Incidents

json-to-simple-graphql-schema

npm

MAL-2026-4590

Malicious code in json-to-simple-graphql-schema (npm)

Malware
May 2026

etherproxy-lite

npm

MAL-2026-4552

Malicious code in etherproxy-lite (npm)

Malware
May 2026

@izumiswap/sdk

npm

MAL-2026-4396

Malicious code in @izumiswap/sdk (npm)

Malware
May 2026

motion-tool

npm

MAL-2026-4615

Malicious code in motion-tool (npm)

Malware
May 2026

happy-dlscord.js

npm

MAL-2026-4575

Malicious code in happy-dlscord.js (npm)

Typosquat
May 2026

skills-detector

npm

MAL-2026-4670

Malicious code in skills-detector (npm)

Malware
May 2026

@databus-service-ui/ui-event

npm

MAL-2026-4351

Malicious code in @databus-service-ui/ui-event (npm)

Malware
May 2026

@databus-service-ui/scroll-up-content

npm

MAL-2026-4378

Malicious code in @databus-service-ui/scroll-up-content (npm)

Dep Confusion
May 2026

@nolimit-x/win32-x64

npm

MAL-2026-4408

Malicious code in @nolimit-x/win32-x64 (npm)

Malware
May 2026

koishi-plugin-yuan

npm

MAL-2026-4596

Malicious code in koishi-plugin-yuan (npm)

Malware
May 2026

@service-suppliers/suppliers

npm

MAL-2026-4438

Malicious code in @service-suppliers/suppliers (npm)

Malware
May 2026

verify-mycommand

npm

MAL-2026-4344

Malicious code in verify-mycommand (npm)

Malware
May 2026

@service-user-notifications/set_notifications_not_removable

npm

MAL-2026-4439

Malicious code in @service-user-notifications/set_notifications_not_removable (npm)

Malware
May 2026

@service-suppliers/set_selected_supplier

npm

MAL-2026-4437

Malicious code in @service-suppliers/set_selected_supplier (npm)

Malware
May 2026

@service-suppliers/select-supplier-watcher-saga

npm

MAL-2026-4436

Malicious code in @service-suppliers/select-supplier-watcher-saga (npm)

Dep Confusion
May 2026

@service-suppliers/fetch_suppliers_action_saga

npm

MAL-2026-4435

Malicious code in @service-suppliers/fetch_suppliers_action_saga (npm)

Malware
May 2026

normalize-path-seq

npm

MAL-2026-4622

Malicious code in normalize-path-seq (npm)

Typosquat
May 2026

@beyondbday/vibe-terminal

npm

MAL-2026-4368

Malicious code in @beyondbday/vibe-terminal (npm)

Malware
May 2026

gehneb

npm

MAL-2026-4570

Malicious code in gehneb (npm)

Malware
May 2026

aes-decode-runner-pro

npm

MAL-2026-4475

Malicious code in aes-decode-runner-pro (npm)

Malware
May 2026

@polka-ui/loader

npm

MAL-2026-4420

Malicious code in @polka-ui/loader (npm)

Malware
May 2026

@loans/vehicles-api

npm

MAL-2026-4404

Malicious code in @loans/vehicles-api (npm)

Malware
May 2026

jsontoken-extend

npm

MAL-2026-4592

Malicious code in jsontoken-extend (npm)

Typosquat
May 2026

vue-compiler-sfc-plugin

npm

MAL-2026-4707

Malicious code in vue-compiler-sfc-plugin (npm)

Typosquat
May 2026
Showing 505 - 528 of 214,285
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001