Supply Chain Incidents

Malicious packages, backdoors, typosquats, and dependency confusion attacks

238,182
Total Incidents

arc-diag-util

npm

MAL-2026-4481

Malicious code in arc-diag-util (npm)

Malware
May 2026

@zesyn/zeditor

npm

MAL-2026-4471

Malicious code in @zesyn/zeditor (npm)

Malware
May 2026

@weirdorg/dotenv

npm

MAL-2026-4467

Malicious code in @weirdorg/dotenv (npm)

Malware
May 2026

seekcode

npm

MAL-2026-4667

Malicious code in seekcode (npm)

Typosquat
May 2026

@qwedqwed/axios

npm

MAL-2026-4422

Malicious code in @qwedqwed/axios (npm)

Malware
May 2026

ts-logger-pack

npm

MAL-2026-4199

Malicious code in ts-logger-pack (npm)

Malware
May 2026

terminal-logger-utils

npm

MAL-2026-4198

Malicious code in terminal-logger-utils (npm)

Malware
May 2026

@sec-loans-ui/utils

npm

MAL-2026-4432

Malicious code in @sec-loans-ui/utils (npm)

Malware
May 2026

@riskine-frontend/design-elements

npm

MAL-2026-4425

Malicious code in @riskine-frontend/design-elements (npm)

Dep Confusion
May 2026

openclaw-agent

PyPI

MAL-2026-4183

Malicious code in openclaw-agent (PyPI)

Backdoor
May 2026

react-tracked-tony

npm

MAL-2026-4661

Malicious code in react-tracked-tony (npm)

Typosquat
May 2026

qazaq-cli

npm

MAL-2026-4654

Malicious code in qazaq-cli (npm)

Malware
May 2026

promptbook-cli

npm

MAL-2026-4648

Malicious code in promptbook-cli (npm)

Malware
May 2026

promptbook-mcp

npm

MAL-2026-4649

Malicious code in promptbook-mcp (npm)

Malware
May 2026

fca-official-uzair-rajput

npm

MAL-2026-4560

Malicious code in fca-official-uzair-rajput (npm)

Malware
May 2026

security-env-loader

npm

MAL-2026-4665

Malicious code in security-env-loader (npm)

Malware
May 2026

@touchvue/chat

npm

MAL-2026-4459

Malicious code in @touchvue/chat (npm)

Malware
May 2026

fulcrum-sessions

npm

MAL-2026-4568

Malicious code in fulcrum-sessions (npm)

Malware
May 2026

axiosqqq

npm

MAL-2026-4493

Malicious code in axiosqqq (npm)

Typosquat
May 2026

bucket-protocol-sdk-v2

npm

MAL-2026-4502

Malicious code in bucket-protocol-sdk-v2 (npm)

Typosquat
May 2026

@pluxee-connect/api-client

npm

MAL-2026-4418

Malicious code in @pluxee-connect/api-client (npm)

Malware
May 2026

mcp-server-iehub-proxy

npm

MAL-2026-4608

Malicious code in mcp-server-iehub-proxy (npm)

Malware
May 2026

@tailwind-core/oxide-win32-x64-msvc

npm

MAL-2026-4449

Malicious code in @tailwind-core/oxide-win32-x64-msvc (npm)

Typosquat
May 2026

figma-d2c-utils

npm

MAL-2026-4562

Malicious code in figma-d2c-utils (npm)

Malware
May 2026
Showing 11809 - 11832 of 238,182
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001