Supply Chain Incidents

Malicious packages, backdoors, typosquats, and dependency confusion attacks

228,609
Total Incidents

@tanstack/history

npm

MAL-2026-3463

Malicious code in @tanstack/history (npm)

Malware
May 2026

@tanstack/eslint-plugin-start

npm

MAL-2026-3462

Malicious code in @tanstack/eslint-plugin-start (npm)

Malware
May 2026

@tanstack/eslint-plugin-router

npm

MAL-2026-3461

Malicious code in @tanstack/eslint-plugin-router (npm)

Malware
May 2026

@tanstack/arktype-adapter

npm

MAL-2026-3460

Malicious code in @tanstack/arktype-adapter (npm)

Malware
May 2026

@mistralai/mistralai

npm

MAL-2026-3432

Malicious code in @mistralai/mistralai (npm)

Malware
May 2026

apkeep

PyPI

MAL-2026-3431

Malicious code in apkeep (PyPI)

Typosquat
May 2026

cplace-bmw-emt-mvp

npm

MAL-2026-3430

Malicious code in cplace-bmw-emt-mvp (npm)

Malware
May 2026

openai-spellchecker

PyPI

MAL-2026-3429

Malicious code in openai-spellchecker (PyPI)

Malware
May 2026

crypto-javascri

npm

MAL-2026-3508

Malicious code in crypto-javascri (npm)

Malware
May 2026

@mimecast-ui/charts

npm

MAL-2026-3506

Malicious code in @mimecast-ui/charts (npm)

Malware
May 2026

@mimecast-ui/components

npm

MAL-2026-3507

Malicious code in @mimecast-ui/components (npm)

Malware
May 2026

@cplace-workflow-fe/cf-workflow

npm

MAL-2026-3427

Malicious code in @cplace-workflow-fe/cf-workflow (npm)

Malware
May 2026

xxx-bale

PyPI

MAL-2026-3428

Malicious code in xxx-bale (PyPI)

Malware
May 2026

guarddog

PyPI

GHSA-m5p4-gvpx-4mvr

GuardDog: Unsanitized human-readable scan output allows terminal escape injection from malicious package content

Malware
1 CVE
May 2026

pp-react-v5

npm

MAL-2026-3509

Malicious code in pp-react-v5 (npm)

Malware
May 2026

mpkg123

PyPI

MAL-2026-3426

Malicious code in mpkg123 (PyPI)

Malware
May 2026

xxoo-bale

PyPI

MAL-2026-3425

Malicious code in xxoo-bale (PyPI)

Malware
May 2026

byvendors

npm

MAL-2026-3423

Malicious code in byvendors (npm)

Malware
May 2026

dlocal-cli

PyPI

MAL-2026-3424

Malicious code in dlocal-cli (PyPI)

Typosquat
May 2026

briantreehttp

npm

MAL-2026-3639

Malicious code in briantreehttp (npm)

Typosquat
May 2026

ac-sasskit

npm

MAL-2026-3415

Malicious code in ac-sasskit (npm)

Malware
May 2026

django-b64-img

PyPI

MAL-2026-3413

Malicious code in django-b64-img (PyPI)

Backdoor
May 2026

rsflows-pexml

npm

MAL-2026-3422

Malicious code in rsflows-pexml (npm)

Malware
May 2026

noon-contracts

npm

MAL-2026-3420

Malicious code in noon-contracts (npm)

Malware
May 2026
Showing 3097 - 3120 of 228,609
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001