Supply Chain Incidents

Malicious packages, backdoors, typosquats, and dependency confusion attacks

225,303
Total Incidents

@maxcointech/simple-string-utils

npm

MAL-2026-213

Malicious code in @maxcointech/simple-string-utils (npm)

Malware
Jan 2026

simple-string-utils3

npm

MAL-2026-233

Malicious code in simple-string-utils3 (npm)

Malware
Jan 2026

jz-test-npm

npm

MAL-2026-226

Malicious code in jz-test-npm (npm)

Malware
Jan 2026

luxon-js

npm

MAL-2026-228

Malicious code in luxon-js (npm)

Malware
Jan 2026

inquirer-js

npm

MAL-2026-224

Malicious code in inquirer-js (npm)

Malware
Jan 2026

framer-motion-js

npm

MAL-2026-220

Malicious code in framer-motion-js (npm)

Malware
Jan 2026

jsdom-js

npm

MAL-2026-225

Malicious code in jsdom-js (npm)

Malware
Jan 2026

react-hook-form-js

npm

MAL-2026-232

Malicious code in react-hook-form-js (npm)

Malware
Jan 2026

immer-js

npm

MAL-2026-223

Malicious code in immer-js (npm)

Malware
Jan 2026

huggingface-js

npm

MAL-2026-222

Malicious code in huggingface-js (npm)

Malware
Jan 2026

llamaindex-js

npm

MAL-2026-227

Malicious code in llamaindex-js (npm)

Malware
Jan 2026

pinecone-js

npm

MAL-2026-231

Malicious code in pinecone-js (npm)

Malware
Jan 2026

milvus-js

npm

MAL-2026-229

Malicious code in milvus-js (npm)

Malware
Jan 2026

xml2js-js

npm

MAL-2026-234

Malicious code in xml2js-js (npm)

Malware
Jan 2026

firestore-types

npm

MAL-2026-219

Malicious code in firestore-types (npm)

Malware
Jan 2026

analytics-browser

npm

MAL-2026-214

Malicious code in analytics-browser (npm)

Malware
Jan 2026

auth-types

npm

MAL-2026-215

Malicious code in auth-types (npm)

Malware
Jan 2026

gradle-plugin

npm

MAL-2026-221

Malicious code in gradle-plugin (npm)

Malware
Jan 2026

experimental-utils

npm

MAL-2026-217

Malicious code in experimental-utils (npm)

Malware
Jan 2026

@t4i-cms-components/contact-card

npm

MAL-2026-209

Malicious code in @t4i-cms-components/contact-card (npm)

Malware
Jan 2026

lyonscg

npm

MAL-2026-212

Malicious code in lyonscg (npm)

Malware
Jan 2026

@workleap-ai/shared

npm

MAL-2026-210

Malicious code in @workleap-ai/shared (npm)

Malware
Jan 2026

@workleap-widgets/client

npm

MAL-2026-211

Malicious code in @workleap-widgets/client (npm)

Malware
Jan 2026

@gwp-gtmt-components/event-listener

npm

MAL-2026-208

Malicious code in @gwp-gtmt-components/event-listener (npm)

Malware
Jan 2026
Showing 3097 - 3120 of 225,303
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001