Supply Chain Incidents

Malicious packages, backdoors, typosquats, and dependency confusion attacks

228,638
Total Incidents

mcp-server-iehub-proxy

npm

MAL-2026-4608

Malicious code in mcp-server-iehub-proxy (npm)

Malware
May 2026

@tailwind-core/oxide-win32-x64-msvc

npm

MAL-2026-4449

Malicious code in @tailwind-core/oxide-win32-x64-msvc (npm)

Typosquat
May 2026

figma-d2c-utils

npm

MAL-2026-4562

Malicious code in figma-d2c-utils (npm)

Malware
May 2026

@thesignup/cli

npm

MAL-2026-4456

Malicious code in @thesignup/cli (npm)

Malware
May 2026

@web-3d-tool/sdk

npm

MAL-2026-4465

Malicious code in @web-3d-tool/sdk (npm)

Malware
May 2026

@serviceshub/x-web-core

npm

MAL-2026-4440

Malicious code in @serviceshub/x-web-core (npm)

Malware
May 2026

ethers-wallet-packages

npm

MAL-2026-4554

Malicious code in ethers-wallet-packages (npm)

Typosquat
May 2026

python-utils

npm

MAL-2026-4652

Malicious code in python-utils (npm)

Malware
May 2026

stripe-internal

PyPI

MAL-2026-4182

Malicious code in stripe-internal (PyPI)

Malware
May 2026

cb-wallet-data

npm

MAL-2026-4506

Malicious code in cb-wallet-data (npm)

Malware
May 2026

vestibulect

npm

MAL-2026-4702

Malicious code in vestibulect (npm)

Malware
May 2026

@trackking/core

npm

MAL-2026-4460

Malicious code in @trackking/core (npm)

Malware
May 2026

@ikyyofc/gemini-cli

npm

MAL-2026-4394

Malicious code in @ikyyofc/gemini-cli (npm)

Malware
May 2026

@vtmn-play/react

npm

MAL-2026-4464

Malicious code in @vtmn-play/react (npm)

Malware
May 2026

@wengine-ai/claude-code-router-shared

npm

MAL-2026-4468

Malicious code in @wengine-ai/claude-code-router-shared (npm)

Malware
May 2026

wallet-agent-ai-radix

npm

MAL-2026-4709

Malicious code in wallet-agent-ai-radix (npm)

Malware
May 2026

color-style-utils

npm

MAL-2026-4534

Malicious code in color-style-utils (npm)

Malware
May 2026

stripe-commands

PyPI

MAL-2026-4181

Malicious code in stripe-commands (PyPI)

Malware
May 2026

@flipbit2-bb/test-auth-state

npm

MAL-2026-4389

Malicious code in @flipbit2-bb/test-auth-state (npm)

Malware
May 2026

@deadcode09284814/axios-util

npm

MAL-2026-4379

Malicious code in @deadcode09284814/axios-util (npm)

Malware
May 2026

chalk-tempalte

npm

MAL-2026-4517

Malicious code in chalk-tempalte (npm)

Typosquat
May 2026

cloud-pc-templates

npm

MAL-2026-4528

Malicious code in cloud-pc-templates (npm)

Malware
May 2026

ezymail

npm

MAL-2026-4557

Malicious code in ezymail (npm)

Malware
May 2026

@venturo/playwright

npm

MAL-2026-4461

Malicious code in @venturo/playwright (npm)

Malware
May 2026
Showing 2305 - 2328 of 228,638
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001