Supply Chain Incidents

Malicious packages, backdoors, typosquats, and dependency confusion attacks

225,303
Total Incidents

worldnormal

npm

MAL-2026-403

Malicious code in worldnormal (npm)

Malware
Jan 2026

manage-root

npm

MAL-2026-393

Malicious code in manage-root (npm)

Malware
Jan 2026

private-internal-sdk

npm

MAL-2026-396

Malicious code in private-internal-sdk (npm)

Malware
Jan 2026

worldposition

npm

MAL-2026-404

Malicious code in worldposition (npm)

Malware
Jan 2026

vworldviewdir

npm

MAL-2026-402

Malicious code in vworldviewdir (npm)

Malware
Jan 2026

@mikudev/ridwan-baileys-mod

npm

MAL-2026-382

Malicious code in @mikudev/ridwan-baileys-mod (npm)

Malware
Jan 2026

@mikudev/signal

npm

MAL-2026-384

Malicious code in @mikudev/signal (npm)

Malware
Jan 2026

@mikudev/beles

npm

MAL-2026-381

Malicious code in @mikudev/beles (npm)

Malware
Jan 2026

@mikudev/ridwan-signal

npm

MAL-2026-383

Malicious code in @mikudev/ridwan-signal (npm)

Malware
Jan 2026

torbaileys

npm

MAL-2026-399

Malicious code in torbaileys (npm)

Malware
Jan 2026

tor-libsignal

npm

MAL-2026-398

Malicious code in tor-libsignal (npm)

Malware
Jan 2026

genki-analytics

npm

MAL-2026-389

Malicious code in genki-analytics (npm)

Malware
Jan 2026

charlie_charlie_kirky

npm

MAL-2026-388

Malicious code in charlie_charlie_kirky (npm)

Malware
Jan 2026

recaptcha-cors

npm

MAL-2026-397

Malicious code in recaptcha-cors (npm)

Malware
Jan 2026

n8n-nodes-zl-vietts

npm

MAL-2026-394

Malicious code in n8n-nodes-zl-vietts (npm)

Malware
Jan 2026

@diendh/n8n-nodes-tiktok-v2

npm

MAL-2026-378

Malicious code in @diendh/n8n-nodes-tiktok-v2 (npm)

Malware
Jan 2026

blocks-builder-manifest-generator

npm

MAL-2026-385

Malicious code in blocks-builder-manifest-generator (npm)

Malware
Jan 2026

natateste

npm

MAL-2026-395

Malicious code in natateste (npm)

Malware
Jan 2026

victim-package-c

npm

MAL-2026-401

Malicious code in victim-package-c (npm)

Malware
Jan 2026

victim-package-b

npm

MAL-2026-400

Malicious code in victim-package-b (npm)

Malware
Jan 2026

potdf

npm

MAL-2026-377

Malicious code in potdf (npm)

Malware
Jan 2026

coolpackage2323

PyPI

MAL-2026-376

Malicious code in coolpackage2323 (PyPI)

Malware
Jan 2026

spellcheckerpy

PyPI

MAL-2026-375

Malicious code in spellcheckerpy (PyPI)

Malware
Jan 2026

github.com/esm-dev/esm.sh

Go

GHSA-2657-3c98-63jq

esm.sh has a path traversal in extractPackageTarball enables file writes from malicious packages

Malware
1 CVE
Jan 2026
Showing 2929 - 2952 of 225,303
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001