Supply Chain Incidents

Malicious packages, backdoors, typosquats, and dependency confusion attacks

228,609
Total Incidents

@easy-entry/routes

npm

MAL-2026-5410

Malicious code in @easy-entry/routes (npm)

Malware
Jun 2026

@easy-entry/landing-routes

npm

MAL-2026-5408

Malicious code in @easy-entry/landing-routes (npm)

Malware
Jun 2026

shopify-app-bridge-internal

npm

MAL-2026-5452

Malicious code in shopify-app-bridge-internal (npm)

Malware
Jun 2026

@sourceflow-uk/sourceflow-tracker

npm

MAL-2026-5430

Malicious code in @sourceflow-uk/sourceflow-tracker (npm)

Malware
Jun 2026

ac_calendar_ts

npm

MAL-2026-5434

Malicious code in ac_calendar_ts (npm)

Malware
Jun 2026

ac_semantic-ui_ts

npm

MAL-2026-5435

Malicious code in ac_semantic-ui_ts (npm)

Malware
Jun 2026

@oplus/obus-web-sdk

npm

MAL-2026-5425

Malicious code in @oplus/obus-web-sdk (npm)

Malware
Jun 2026

@oplus/obus-web-sdk-plugin-recovery

npm

MAL-2026-5426

Malicious code in @oplus/obus-web-sdk-plugin-recovery (npm)

Dep Confusion
Jun 2026

@oplus/obus-core

npm

MAL-2026-5424

Malicious code in @oplus/obus-core (npm)

Dep Confusion
Jun 2026

tao-subnet-metrics

PyPI

MAL-2026-5457

Malicious code in tao-subnet-metrics (PyPI)

Malware
Jun 2026

ultimate-ai-power

PyPI

MAL-2026-5458

Malicious code in ultimate-ai-power (PyPI)

Malware
Jun 2026

comos-sdk

npm

MAL-2026-5405

Malicious code in comos-sdk (npm)

Malware
Jun 2026

cubifyanything

PyPI

MAL-2026-5404

Malicious code in cubifyanything (PyPI)

Malware
Jun 2026

@0xlr/sentry-web

npm

MAL-2026-5387

Malicious code in @0xlr/sentry-web (npm)

Malware
Jun 2026

@0xlr/clerk-auth

npm

MAL-2026-5385

Malicious code in @0xlr/clerk-auth (npm)

Malware
Jun 2026

@0xlr/prisma-client-js

npm

MAL-2026-5386

Malicious code in @0xlr/prisma-client-js (npm)

Malware
Jun 2026

@0xlr/vercel-analytics

npm

MAL-2026-5391

Malicious code in @0xlr/vercel-analytics (npm)

Malware
Jun 2026

@0xlr/stripe-frontend

npm

MAL-2026-5389

Malicious code in @0xlr/stripe-frontend (npm)

Malware
Jun 2026

@0xlr/stripe-checkout-js

npm

MAL-2026-5388

Malicious code in @0xlr/stripe-checkout-js (npm)

Typosquat
Jun 2026

ui-weave

npm

MAL-2026-5406

Malicious code in ui-weave (npm)

Malware
Jun 2026

@0xlr/supabase-db

npm

MAL-2026-5390

Malicious code in @0xlr/supabase-db (npm)

Malware
Jun 2026

kraken-ui

npm

MAL-2026-5399

Malicious code in kraken-ui (npm)

Dep Confusion
Jun 2026

@sflyinc-knapsack/shutterfly-react

npm

MAL-2026-5393

Malicious code in @sflyinc-knapsack/shutterfly-react (npm)

Malware
Jun 2026

@open-banking/cabinet-providers

npm

MAL-2026-5392

Malicious code in @open-banking/cabinet-providers (npm)

Malware
Jun 2026
Showing 1129 - 1152 of 228,609
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001