Supply Chain Incidents

Malicious packages, backdoors, typosquats, and dependency confusion attacks

228,638
Total Incidents

pulse-axios

npm

MAL-2026-4651

Malicious code in pulse-axios (npm)

Typosquat
May 2026

rdflib

npm

MAL-2026-4659

Malicious code in rdflib (npm)

Malware
May 2026

stripe-utils

PyPI

MAL-2026-4180

Malicious code in stripe-utils (PyPI)

Malware
May 2026

axois-utils

npm

MAL-2026-4494

Malicious code in axois-utils (npm)

Malware
May 2026

carvus-lens

npm

MAL-2026-4505

Malicious code in carvus-lens (npm)

Malware
May 2026

polymarket-clob-client

npm

MAL-2026-4643

Malicious code in polymarket-clob-client (npm)

Malware
May 2026

@shinzepelly/libsignal-node

npm

MAL-2026-4443

Malicious code in @shinzepelly/libsignal-node (npm)

Malware
May 2026

@tailwind-core/webpack

npm

MAL-2026-4452

Malicious code in @tailwind-core/webpack (npm)

Typosquat
May 2026

@solarcraft/observix

npm

MAL-2026-4446

Malicious code in @solarcraft/observix (npm)

Backdoor
May 2026

get-deps-path

npm

MAL-2026-4571

Malicious code in get-deps-path (npm)

Backdoor
May 2026

fca-eryxenx

npm

MAL-2026-4559

Malicious code in fca-eryxenx (npm)

Malware
May 2026

customerdigital-ui-containers-lib

npm

MAL-2026-4543

Malicious code in customerdigital-ui-containers-lib (npm)

Malware
May 2026

code-tool-langfuse

npm

MAL-2026-4532

Malicious code in code-tool-langfuse (npm)

Malware
May 2026

hpsetup

npm

MAL-2026-4579

Malicious code in hpsetup (npm)

Malware
May 2026

jsonbson

npm

MAL-2026-4591

Malicious code in jsonbson (npm)

Typosquat
May 2026

@mcpassure/mcp-cnes

npm

MAL-2026-4407

Malicious code in @mcpassure/mcp-cnes (npm)

Malware
May 2026

@mcpassure/mcp-anvisa-bulario

npm

MAL-2026-4406

Malicious code in @mcpassure/mcp-anvisa-bulario (npm)

Malware
May 2026

@rocketreach/rr-components

npm

MAL-2026-4427

Malicious code in @rocketreach/rr-components (npm)

Malware
May 2026

@tailwind-core/postcss

npm

MAL-2026-4450

Malicious code in @tailwind-core/postcss (npm)

Typosquat
May 2026

crypto-javascript

npm

MAL-2026-4542

Malicious code in crypto-javascript (npm)

Typosquat
May 2026

@tailwind-core/vite

npm

MAL-2026-4451

Malicious code in @tailwind-core/vite (npm)

Typosquat
May 2026

lokal-mcp

npm

MAL-2026-4602

Malicious code in lokal-mcp (npm)

Malware
May 2026

tubebrain

npm

MAL-2026-4694

Malicious code in tubebrain (npm)

Malware
May 2026

to-cms

npm

MAL-2026-4693

Malicious code in to-cms (npm)

Malware
May 2026
Showing 2329 - 2352 of 228,638
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001