Supply Chain Incidents

Malicious packages, backdoors, typosquats, and dependency confusion attacks

228,448
Total Incidents

@mastra/hono

npm

MAL-2026-5950

Malicious code in @mastra/hono (npm)

Malware
Jun 2026

@mastra/datadog

npm

MAL-2026-5943

Malicious code in @mastra/datadog (npm)

Malware
Jun 2026

@mastra/editor

npm

MAL-2026-5946

Malicious code in @mastra/editor (npm)

Malware
Jun 2026

@mastra/otel-bridge

npm

MAL-2026-5958

Malicious code in @mastra/otel-bridge (npm)

Malware
Jun 2026

@mastra/dynamodb

npm

MAL-2026-5945

Malicious code in @mastra/dynamodb (npm)

Malware
Jun 2026

@mastra/duckdb

npm

MAL-2026-5944

Malicious code in @mastra/duckdb (npm)

Malware
Jun 2026

@mastra/evals

npm

MAL-2026-5947

Malicious code in @mastra/evals (npm)

Malware
Jun 2026

@mastra/schema-compat

npm

MAL-2026-5963

Malicious code in @mastra/schema-compat (npm)

Malware
Jun 2026

@mastra/langfuse

npm

MAL-2026-5952

Malicious code in @mastra/langfuse (npm)

Malware
Jun 2026

@mastra/ai-sdk

npm

MAL-2026-5939

Malicious code in @mastra/ai-sdk (npm)

Malware
Jun 2026

@mastra/mcp

npm

MAL-2026-5955

Malicious code in @mastra/mcp (npm)

Malware
Jun 2026

@mastra/pg

npm

MAL-2026-5959

Malicious code in @mastra/pg (npm)

Malware
Jun 2026

@mastra/libsql

npm

MAL-2026-5954

Malicious code in @mastra/libsql (npm)

Malware
Jun 2026

mastra

npm

MAL-2026-5965

Malicious code in mastra (npm)

Malware
Jun 2026

abuden21

npm

MAL-2026-5937

Malicious code in abuden21 (npm)

Malware
Jun 2026

speed4

npm

MAL-2026-5938

Malicious code in speed4 (npm)

Malware
Jun 2026

backoffice-charges-module

npm

MAL-2026-5929

Malicious code in backoffice-charges-module (npm)

Typosquat
Jun 2026

bubblestr

npm

MAL-2026-5930

Malicious code in bubblestr (npm)

Malware
Jun 2026

tw-theme-kit

npm

MAL-2026-5935

Malicious code in tw-theme-kit (npm)

Malware
Jun 2026

vite-config-field

npm

MAL-2026-5936

Malicious code in vite-config-field (npm)

Malware
Jun 2026

react-vite-assert

npm

MAL-2026-5933

Malicious code in react-vite-assert (npm)

Malware
Jun 2026

ssr-auth-sync

npm

MAL-2026-5934

Malicious code in ssr-auth-sync (npm)

Malware
Jun 2026

package-uploader

npm

MAL-2026-5932

Malicious code in package-uploader (npm)

Malware
Jun 2026

mci-sdk

npm

MAL-2026-5931

Malicious code in mci-sdk (npm)

Malware
Jun 2026
Showing 433 - 456 of 228,448
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001