What we've been watching.
Recent supply-chain compromises across npm, PyPI, RubyGems, crates.io, Go modules, Packagist, NuGet, Open VSX, Docker Hub, and GitHub Actions. Curated from public vendor advisories. We list every version we can verify so the scanner picks them up directly: 613 package–version pairs across 36 incidents and counting.
- Critical11 May 2026178 packages tracked
TanStack + @uipath mini-Shai-Hulud compromise
Between 19:20–19:26 UTC on 2026-05-11, an attacker pushed malicious versions across @tanstack/*, @uipath/*, @mistralai/*, @squawk/*, @tallyui/*, @mesadev/*, @cap-js/*, and many smaller packages by chaining `pull_request_target`, GitHub Actions cache poisoning, and runtime memory extraction of an OIDC token from the runner. Same credential-stealing worm payload as the April SAP campaign. Wiz updated the affected-package table on 2026-05-12.
npmPyPIAffected packages180 packages · 415 versions
- npm
@beproduct/nestjs-auth0.1.20.1.30.1.40.1.50.1.60.1.70.1.80.1.90.1.100.1.110.1.120.1.130.1.140.1.150.1.160.1.170.1.180.1.19 - npm
@cap-js/db-service2.10.1 - npm
@cap-js/postgres2.2.2 - npm
@cap-js/sqlite2.2.2 - npm
@dirigible-ai/sdk0.6.20.6.3 - npm
@draftauth/client0.2.10.2.2 - npm
@draftauth/core0.13.10.13.2 - npm
@draftlab/auth0.24.10.24.2 - npm
@draftlab/auth-router0.5.10.5.2 - npm
@draftlab/db0.16.10.16.2 - npm
@mesadev/rest0.28.3 - npm
@mesadev/saguaro0.4.22 - npm
@mesadev/sdk0.28.3 - npm
@mistralai/mistralai2.2.22.2.32.2.4 - npm
@mistralai/mistralai-azure1.7.11.7.21.7.3 - npm
@mistralai/mistralai-gcp1.7.11.7.21.7.3 - npm
@ml-toolkit-ts/preprocessing1.0.21.0.3 - npm
@ml-toolkit-ts/xgboost1.0.31.0.4 - npm
@opensearch-project/opensearch3.5.33.6.23.7.03.8.0 - npm
@squawk/airport-data0.7.40.7.50.7.60.7.70.7.8 - npm
@squawk/airports0.6.20.6.30.6.40.6.50.6.6 - npm
@squawk/airspace0.8.10.8.20.8.30.8.40.8.5 - npm
@squawk/airspace-data0.5.30.5.40.5.50.5.60.5.7 - npm
@squawk/airway-data0.5.40.5.50.5.60.5.70.5.8 - npm
@squawk/airways0.4.20.4.30.4.40.4.50.4.6 - npm
@squawk/fix-data0.6.40.6.50.6.60.6.70.6.8 - npm
@squawk/fixes0.3.20.3.30.3.40.3.50.3.6 - npm
@squawk/flight-math0.5.40.5.50.5.60.5.70.5.8 - npm
@squawk/flightplan0.5.20.5.30.5.40.5.50.5.6 - npm
@squawk/geo0.4.40.4.50.4.60.4.70.4.8 - npm
@squawk/icao-registry0.5.20.5.30.5.40.5.50.5.6 - npm
@squawk/icao-registry-data0.8.40.8.50.8.60.8.70.8.8 - npm
@squawk/mcp0.9.10.9.20.9.30.9.40.9.5 - npm
@squawk/navaid-data0.6.40.6.50.6.60.6.70.6.8 - npm
@squawk/navaids0.4.20.4.30.4.40.4.50.4.6 - npm
@squawk/notams0.3.60.3.70.3.80.3.90.3.10 - npm
@squawk/procedure-data0.7.30.7.40.7.50.7.60.7.7 - npm
@squawk/procedures0.5.20.5.30.5.40.5.50.5.6 - npm
@squawk/types0.8.10.8.20.8.30.8.40.8.5 - npm
@squawk/units0.4.30.4.40.4.50.4.60.4.7 - npm
@squawk/weather0.5.60.5.70.5.80.5.90.5.10 - npm
@supersurkhet/cli0.0.20.0.30.0.40.0.50.0.60.0.7 - npm
@supersurkhet/sdk0.0.20.0.30.0.40.0.50.0.60.0.7 - npm
@tallyui/components1.0.11.0.21.0.3 - npm
@tallyui/connector-medusa1.0.11.0.21.0.3 - npm
@tallyui/connector-shopify1.0.11.0.21.0.3 - npm
@tallyui/connector-vendure1.0.11.0.21.0.3 - npm
@tallyui/connector-woocommerce1.0.11.0.21.0.3 - npm
@tallyui/core0.2.10.2.20.2.3 - npm
@tallyui/database1.0.11.0.21.0.3 - npm
@tallyui/pos0.1.10.1.20.1.3 - npm
@tallyui/storage-sqlite0.2.10.2.20.2.3 - npm
@tallyui/theme0.2.10.2.20.2.3 - npm
@tanstack/arktype-adapter1.166.121.166.15 - npm
@tanstack/eslint-plugin-router1.161.91.161.12 - npm
@tanstack/eslint-plugin-start0.0.40.0.7 - npm
@tanstack/history1.161.91.161.12 - npm
@tanstack/nitro-v2-vite-plugin1.154.121.154.15 - npm
@tanstack/react-router1.169.51.169.8 - npm
@tanstack/react-router-devtools1.166.161.166.19 - npm
@tanstack/react-router-ssr-query1.166.151.166.18 - npm
@tanstack/react-start1.167.681.167.71 - npm
@tanstack/react-start-client1.166.511.166.54 - npm
@tanstack/react-start-rsc0.0.470.0.50 - npm
@tanstack/react-start-server1.166.551.166.58 - npm
@tanstack/router-cli1.166.461.166.49 - npm
@tanstack/router-core1.169.51.169.8 - npm
@tanstack/router-devtools1.166.161.166.19 - npm
@tanstack/router-devtools-core1.167.61.167.9 - npm
@tanstack/router-generator1.166.451.166.48 - npm
@tanstack/router-plugin1.167.381.167.41 - npm
@tanstack/router-ssr-query-core1.168.31.168.6 - npm
@tanstack/router-utils1.161.111.161.14 - npm
@tanstack/router-vite-plugin1.166.531.166.56 - npm
@tanstack/solid-router1.169.51.169.8 - npm
@tanstack/solid-router-devtools1.166.161.166.19 - npm
@tanstack/solid-router-ssr-query1.166.151.166.18 - npm
@tanstack/solid-start1.167.651.167.68 - npm
@tanstack/solid-start-client1.166.501.166.53 - npm
@tanstack/solid-start-server1.166.541.166.57 - npm
@tanstack/start-client-core1.168.51.168.8 - npm
@tanstack/start-fn-stubs1.161.91.161.12 - npm
@tanstack/start-plugin-core1.169.231.169.26 - npm
@tanstack/start-server-core1.167.331.167.36 - npm
@tanstack/start-static-server-functions1.166.441.166.47 - npm
@tanstack/start-storage-context1.166.381.166.41 - npm
@tanstack/valibot-adapter1.166.121.166.15 - npm
@tanstack/virtual-file-routes1.161.101.161.13 - npm
@tanstack/vue-router1.169.51.169.8 - npm
@tanstack/vue-router-devtools1.166.161.166.19 - npm
@tanstack/vue-router-ssr-query1.166.151.166.18 - npm
@tanstack/vue-start1.167.611.167.64 - npm
@tanstack/vue-start-client1.166.461.166.49 - npm
@tanstack/vue-start-server1.166.501.166.53 - npm
@tanstack/zod-adapter1.166.121.166.15 - npm
@taskflow-corp/cli0.1.240.1.250.1.260.1.270.1.280.1.29 - npm
@tolka/cli1.0.21.0.31.0.41.0.51.0.6 - npm
@uipath/access-policy-sdk0.3.1 - npm
@uipath/access-policy-tool0.3.1 - npm
@uipath/admin-tool0.1.1 - npm
@uipath/agent-sdk1.0.2 - npm
@uipath/agent-tool1.0.1 - npm
@uipath/agent.sdk0.0.18 - npm
@uipath/aops-policy-tool0.3.1 - npm
@uipath/ap-chat1.5.7 - npm
@uipath/api-workflow-tool1.0.1 - npm
@uipath/apollo-core5.9.2 - npm
@uipath/apollo-react4.24.5 - npm
@uipath/apollo-wind2.16.2 - npm
@uipath/auth1.0.1 - npm
@uipath/case-tool1.0.1 - npm
@uipath/cli1.0.1 - npm
@uipath/codedagent-tool1.0.1 - npm
@uipath/codedagents-tool0.1.12 - npm
@uipath/codedapp-tool1.0.1 - npm
@uipath/common1.0.1 - npm
@uipath/context-grounding-tool0.1.1 - npm
@uipath/data-fabric-tool1.0.2 - npm
@uipath/docsai-tool1.0.1 - npm
@uipath/filesystem1.0.1 - npm
@uipath/flow-tool1.0.2 - npm
@uipath/functions-tool1.0.1 - npm
@uipath/gov-tool0.3.1 - npm
@uipath/identity-tool0.1.1 - npm
@uipath/insights-sdk1.0.1 - npm
@uipath/insights-tool1.0.1 - npm
@uipath/integrationservice-sdk1.0.2 - npm
@uipath/integrationservice-tool1.0.2 - npm
@uipath/llmgw-tool1.0.1 - npm
@uipath/maestro-sdk1.0.1 - npm
@uipath/maestro-tool1.0.1 - npm
@uipath/orchestrator-tool1.0.1 - npm
@uipath/packager-tool-apiworkflow0.0.19 - npm
@uipath/packager-tool-bpmn0.0.9 - npm
@uipath/packager-tool-case0.0.9 - npm
@uipath/packager-tool-connector0.0.19 - npm
@uipath/packager-tool-flow0.0.19 - npm
@uipath/packager-tool-functions0.1.1 - npm
@uipath/packager-tool-webapp1.0.6 - npm
@uipath/packager-tool-workflowcompiler0.0.16 - npm
@uipath/packager-tool-workflowcompiler-browser0.0.34 - npm
@uipath/platform-tool1.0.1 - npm
@uipath/project-packager1.1.16 - npm
@uipath/resource-tool1.0.1 - npm
@uipath/resourcecatalog-tool0.1.1 - npm
@uipath/resources-tool0.1.11 - npm
@uipath/robot1.3.4 - npm
@uipath/rpa-legacy-tool1.0.1 - npm
@uipath/rpa-tool0.9.5 - npm
@uipath/solution-packager0.0.35 - npm
@uipath/solution-tool1.0.1 - npm
@uipath/solutionpackager-sdk1.0.11 - npm
@uipath/solutionpackager-tool-core0.0.34 - npm
@uipath/tasks-tool1.0.1 - npm
@uipath/telemetry0.0.7 - npm
@uipath/test-manager-tool1.0.2 - npm
@uipath/tool-workflowcompiler0.0.12 - npm
@uipath/traces-tool1.0.1 - npm
@uipath/ui-widgets-multi-file-upload1.0.1 - npm
@uipath/uipath-python-bridge1.0.1 - npm
@uipath/vertical-solutions-tool1.0.1 - npm
@uipath/vss0.1.6 - npm
@uipath/widget.sdk1.2.3 - npm
agentwork-cli0.1.40.1.5 - npm
cmux-agent-mcp0.1.30.1.40.1.50.1.60.1.70.1.8 - npm
cross-stitch1.1.31.1.41.1.51.1.61.1.7 - npm
git-branch-selector1.3.31.3.41.3.51.3.61.3.7 - npm
git-git-git1.0.81.0.91.0.101.0.111.0.12 - npm
guardrails-ai0.10.1 - PyPI
guardrails-ai0.10.1 - npm
intercom-client7.0.4 - npm
lightning2.6.22.6.3 - npm
mbt1.2.48 - npm
mistralai2.4.6 - PyPI
mistralai2.4.6 - npm
ml-toolkit-ts1.0.41.0.5 - npm
nextmove-mcp0.1.30.1.40.1.50.1.60.1.7 - npm
safe-action0.8.30.8.4 - npm
ts-dna3.0.13.0.23.0.33.0.43.0.5 - npm
wot-api0.8.10.8.20.8.30.8.4
npm-2026-05-shai-hulud-tanstackSource advisory - npm
- High1 May 202616 packages tracked
BufferZoneCorp sleeper attack on RubyGems + Go modules
Socket disclosed a coordinated sleeper-package campaign attributed to the GitHub org `BufferZoneCorp` (and RubyGems user `knot-theory`). Initially-clean Ruby gems and Go modules were updated to malicious versions. The Ruby side harvests env vars, SSH keys, AWS secrets, .npmrc, .netrc, GitHub CLI config, and RubyGems credentials; the Go side tampers with GitHub Actions workflows, injects fake executables, and adds SSH persistence via authorized_keys. First confirmed 2026 RubyGems + Go module supply-chain campaign.
GoRubyGemsAffected packages16 packages · 0 versions
- Go
github.com/BufferZoneCorp/config-loader - Go
github.com/BufferZoneCorp/go-envconfig - Go
github.com/BufferZoneCorp/go-metrics-sdk - Go
github.com/BufferZoneCorp/go-retryablehttp - Go
github.com/BufferZoneCorp/go-stdlib-ext - Go
github.com/BufferZoneCorp/go-weather-sdk - Go
github.com/BufferZoneCorp/grpc-client - Go
github.com/BufferZoneCorp/log-core - Go
github.com/BufferZoneCorp/net-helper - RubyGems
knot-activesupport-logger - RubyGems
knot-date-utils-rb - RubyGems
knot-devise-jwt-helper - RubyGems
knot-rack-session-store - RubyGems
knot-rails-assets-pipeline - RubyGems
knot-rspec-formatter-json - RubyGems
knot-simple-formatter
multi-2026-05-01-bufferzonecorp-rubygems-goSource advisory - Go
- Critical30 Apr 20263 packages tracked
PyTorch Lightning + intercom-client + intercom-php coordinated push
Mini Shai-Hulud wave 2: coordinated April 30 release of `lightning` 2.6.2/2.6.3 (PyPI), `intercom-client` 7.0.4/7.0.5 (npm), and `intercom/intercom-php` 5.0.2 (Packagist) carrying the same Bun-based credential stealer used in the SAP/@cap-js wave. ~11.7MB `router_runtime.js` fires preinstall on npm; a `.pth` file fires at every Python import on PyPI. Worm propagation via stolen GitHub PATs labelled "OhNoWhatsGoingOnWithGitHub:".
npmPackagistPyPIAffected packages3 packages · 5 versions
- npm
intercom-client7.0.47.0.5 - Packagist
intercom/intercom-php5.0.2 - PyPI
lightning2.6.22.6.3
multi-2026-04-30-mini-shai-hulud-wave2Source advisory - npm
- High29 Apr 20269 packages tracked
DPRK "PromptMink" campaign uses AI agents to insert @validate-sdk/v2 dependency
ReversingLabs traced a DPRK Famous Chollima / UNC1069 campaign that began with `@hash-validator/v2` in Sept 2025 and evolved through Feb 28, 2026 to insert `@validate-sdk/v2` as the malicious dependency of benign-looking "bait" SDKs aimed at AI coding agents. One AI-authored commit pulled `@solana-launchpad/sdk` into a crypto trading repo. Phase 4 in March 2026 used Rust NAPI modules and 85MB Node SEA bundles to exfiltrate full source trees. 300+ malicious package versions across 60+ unique packages observed.
npmPyPIAffected packages9 packages · 22 versions
- npm
@hash-validator/v2 - npm
@meme-sdk/trade - npm
@pumpfun-ipfs/sdk - npm
@solana-ipfs/sdk - npm
@solana-launchpad/sdk - npm
@solmasterv3/solana-metadata-sdk - npm
@validate-ethereum-address/core - npm
@validate-sdk/v21.22.111.22.121.22.131.22.141.22.151.22.161.22.171.22.181.22.191.22.201.22.211.22.221.22.231.22.241.22.251.22.261.22.271.22.281.22.291.22.301.22.31 - PyPI
scraper-npm1.0.4
multi-2026-04-29-promptmink-validate-sdkSource advisory - npm
- Critical29 Apr 20264 packages tracked
SAP / @cap-js mini-Shai-Hulud campaign
Mini-Shai-Hulud-style attack against SAP-related npm packages on 2026-04-29 09:55–12:14 UTC. Preinstall `setup.mjs` downloads the Bun runtime, runs an obfuscated `execution.js` that exfils GitHub/npm tokens, AWS/Azure/GCP secrets, Kubernetes tokens, and browser passwords via the GitHub GraphQL API. Includes a Russian-locale guardrail and persistence via .claude/ and .vscode/ poisoning.
npmAffected packages4 packages · 4 versions
- npm
@cap-js/db-service2.10.1 - npm
@cap-js/postgres2.2.2 - npm
@cap-js/sqlite2.2.2 - npm
mbt1.2.48
npm-2026-04-sap-cap-jsSource advisory - npm
- Critical24 Apr 20262 packages tracked
elementary-data PyPI package backdoored via GitHub Actions injection
An attacker (account `realtungtungtungsahur`) exploited a script-injection flaw in the `elementary-data` release workflow via PR comment, then used the workflow token to forge release commit b1e4b1f3 and trigger the legitimate publishing pipeline. PyPI `elementary-data` 0.23.3 and ghcr.io/elementary-data/elementary 0.23.3 + `latest` shipped a ~245 KB obfuscated payload in `elementary.pth`. Clean 0.23.4 published April 25.
DockerPyPIAffected packages2 packages · 3 versions
- PyPI
elementary-data0.23.3 - Docker
ghcr.io/elementary-data/elementary0.23.3latest
pypi-2026-04-24-elementary-dataSource advisory - PyPI
- High23 Apr 20261 package tracked
js-logger-pack npm worm uses Hugging Face datasets as malware CDN + exfil store
JFrog found 27 malicious versions of `js-logger-pack` (1.1.0-1.1.27) abusing the Hugging Face repo `Lordplay/system-releases` to fetch cross-platform binaries (Windows/macOS x64/macOS ARM64/Linux) and upload stolen data to private datasets. The malware adds keylogging, clipboard capture, browser-session and Telegram Desktop theft, plus an operator command channel.
npmAffected packages1 package · 28 versions
- npm
js-logger-pack1.1.01.1.11.1.21.1.31.1.41.1.51.1.61.1.71.1.81.1.91.1.101.1.111.1.121.1.131.1.141.1.151.1.161.1.171.1.181.1.191.1.201.1.211.1.221.1.231.1.241.1.251.1.261.1.27
npm-2026-04-23-js-logger-pack-huggingfaceSource advisory - npm
- Critical22 Apr 20261 package tracked
Xinference PyPI package backdoored on import
JFrog flagged three consecutive `xinference` releases (2.6.0-2.6.2) on PyPI carrying a TeamPCP-style payload embedded in `xinference/__init__.py` that fires on import. The malware base64-encodes a stage-1 wrapper containing the comment `# hacked by teampcp`, then spawns a detached subprocess that bundles harvested data into `love.tar.gz` and POSTs it with a custom `X-QT-SR: 14` header. TeamPCP publicly denied involvement, claiming a copycat. 600,000+ downloads of malicious wheels.
PyPIAffected packages1 package · 3 versions
- PyPI
xinference2.6.02.6.12.6.2
pypi-2026-04-22-xinference-teampcpSource advisory - PyPI
- Critical22 Apr 20263 packages tracked
Checkmarx KICS Docker images + Open VSX extensions compromised (TeamPCP)
Docker and Socket jointly disclosed a multi-stage compromise of Checkmarx KICS Docker images and Checkmarx VS Code / Open VSX extensions. Trojanised extensions silently install an MCP addon executed via Bun, while the Docker images include a modified KICS binary that encrypts scan output and exfiltrates it. TeamPCP claimed responsibility.
DockerOpen VSXAffected packages3 packages · 11 versions
- Open VSX
checkmarx.ast-results2.63.02.66.0 - Open VSX
checkmarx.cx-dev-assist1.17.01.19.0 - Docker
checkmarx/kics2.1.202.1.20-debian2.1.212.1.21-debianalpinedebianlatest
multi-2026-04-22-checkmarx-kics-vsx-dockerSource advisory - Open VSX
- Critical22 Apr 20261 package tracked
@bitwarden/cli 2026.4.0 hijacked via Checkmarx GitHub Actions breach
TeamPCP pushed a malicious `@bitwarden/cli@2026.4.0` to npm between 17:57 and 19:30 ET on April 22, exploiting Bitwarden's use of the breached `checkmarx/ast-github-action`. `bw_setup.js` fetched Bun 1.3.13 from GitHub and ran a payload that targeted SSH, Git, npm, AWS/GCP/Azure, GitHub Actions secrets, and AI/MCP configs (`.claude.json`, `.kiro/settings/mcp.json`), exfiltrating via `audit.checkmarx.cx`. Live ~90 minutes; Bitwarden confirmed no end-user vault data was accessed.
npmAffected packages1 package · 1 version
- npm
@bitwarden/cli2026.4.0
npm-2026-04-22-bitwarden-cli-teampcpSource advisory - npm
- Critical21 Apr 20266 packages tracked
CanisterSprawl: self-propagating npm worm hits pgserve + Namastex packages
Socket and StepSecurity disclosed CanisterSprawl, a self-propagating npm worm that compromised at least 16 versions across Namastex Labs and related publishers from 21 April 2026. The postinstall hook harvests 38 env vars and filesystem secrets, encrypts via AES-256-CBC + RSA-4096, and exfiltrates to an Internet Computer Protocol canister. Stolen npm tokens are reused to publish further malicious versions. Tradecraft matches the earlier TeamPCP CanisterWorm campaign.
npmAffected packages6 packages · 16 versions
- npm
@automagik/genie4.260421.334.260421.344.260421.354.260421.364.260421.374.260421.384.260421.39 - npm
@fairwords/loopback-connector-es1.4.31.4.4 - npm
@fairwords/websocket1.0.381.0.39 - npm
@openwebconcept/design-tokens1.0.3 - npm
@openwebconcept/theme-owc1.0.3 - npm
pgserve1.1.111.1.121.1.13
npm-2026-04-21-canisterworm-pgserve-namastexSource advisory - npm
- High15 Apr 202636 packages tracked
36 fake Strapi plugins on npm deploy persistent implants
Four sock-puppet npm accounts (umarbek1233, kekylf12, tikeqemif26, umar_bektembiev1) uploaded 36 packages over a ~13-hour window impersonating Strapi CMS plugins. Payload evolution moved through 8 variants targeting Redis RCE with cron injection, Docker container escapes, PostgreSQL exploitation on hosts named `prod-strapi`, Python reverse shells on port 4444, and SSH-key backdoors.
npmAffected packages36 packages · 0 versions
- npm
strapi-plugin-advanced-uuid - npm
strapi-plugin-api - npm
strapi-plugin-blurhash - npm
strapi-plugin-cms-tools - npm
strapi-plugin-config - npm
strapi-plugin-content-sync - npm
strapi-plugin-core - npm
strapi-plugin-cron - npm
strapi-plugin-database - npm
strapi-plugin-debug-tools - npm
strapi-plugin-events - npm
strapi-plugin-finseven - npm
strapi-plugin-form - npm
strapi-plugin-guardarian-ext - npm
strapi-plugin-health - npm
strapi-plugin-health-check - npm
strapi-plugin-hextest - npm
strapi-plugin-hooks - npm
strapi-plugin-locale - npm
strapi-plugin-logger - npm
strapi-plugin-monitor - npm
strapi-plugin-nordica - npm
strapi-plugin-nordica-api - npm
strapi-plugin-nordica-cms - npm
strapi-plugin-nordica-deep - npm
strapi-plugin-nordica-lite - npm
strapi-plugin-nordica-recon - npm
strapi-plugin-nordica-stage - npm
strapi-plugin-nordica-sync - npm
strapi-plugin-nordica-tools - npm
strapi-plugin-nordica-vhost - npm
strapi-plugin-notify - npm
strapi-plugin-seed - npm
strapi-plugin-server - npm
strapi-plugin-sitemap-gen - npm
strapi-plugin-sync
npm-2026-04-15-strapi-pluginsSource advisory - npm
- High15 Apr 20261 package tracked
@kindo/selfbot npm package delivers XWorm RAT via 5-stage Astral Warfare chain
JFrog identified `@kindo/selfbot` (XRAY-964727), a video-game-themed Discord selfbot npm package. A 5-stage chain (JS downloader → 250KB obfuscated batch → PowerShell process injection → XOR-decoded shellcode → XWormClient .NET RAT) installed itself against `explorer.exe` with AMSI/ETW evasion.
npmAffected packages1 package · 5 versions
- npm
@kindo/selfbot1.0.01.0.11.0.21.0.31.0.4
npm-2026-04-15-kindo-selfbot-xwormSource advisory - npm
- High14 Apr 20265 packages tracked
5 NuGet packages impersonate Chinese .NET UI libraries with infostealer payload
NuGet publisher `bmrxntfj` shipped five packages on 14 April 2026 within ~13 seconds, grafting a .NET Reactor-protected infostealer onto decompiled legitimate libraries. Across 219 total versions they accumulated ~65k downloads, targeting browser creds, crypto wallets, and SSH keys on Windows .NET dev hosts.
NuGetAffected packages5 packages · 5 versions
- NuGet
IR.DantUI2.1.55 - NuGet
IR.Infrastructure.Core2.1.55 - NuGet
IR.Infrastructure.DataService.Core2.1.55 - NuGet
IR.iplus322.1.55 - NuGet
IR.OscarUI2.1.55
nuget-2026-04-14-chinese-ui-impersonatorsSource advisory - NuGet
- High7 Apr 202614 packages tracked
DPRK Contagious Interview campaign expands across 5 ecosystems
Socket disclosed a fresh wave of DPRK Contagious Interview / FAMOUS CHOLLIMA packages spanning npm, PyPI, Go modules, crates.io, and Packagist. They impersonate logging / license developer tooling and act as staged loaders for credential stealers and RATs across Windows, macOS and Linux. The Windows variant deploys a keylogger and AnyDesk for hands-on access.
crates.ioGonpmPackagistPyPIAffected packages14 packages · 6 versions
- PyPI
apachelicense0.1a1 - npm
debug-fmt - npm
debug-glitz - npm
dev-log-core1.0.5 - PyPI
fluxhttp - Go
github.com/aokisasakidev/mit-license-pkg1.0.2 - Go
github.com/golangorg/formstash1.0.5 - Packagist
golangorg/logkit - PyPI
license-utils-kit0.1rc3 - npm
logger-base - npm
logkitx - crates.io
logtrace1.0.2 - PyPI
logutilkit - npm
pino-debugger
multi-2026-04-07-contagious-interview-5-ecosystemsSource advisory - PyPI
- Medium5 Apr 20261 package tracked
hermes-px PyPI "privacy" AI proxy steals prompts via stolen university infra
JFrog detected `hermes-px`, masquerading as a privacy-preserving AI proxy. It routed requests through Tor to a stolen Tunisian university API and bundled a 246K-character Anthropic Claude system prompt rebranded as "AXIOM-1". It simultaneously exfiltrated all prompts/responses unencrypted to a Supabase endpoint, bypassing Tor and exposing user IPs.
PyPIAffected packages1 package · 0 versions
- PyPI
hermes-px
pypi-2026-04-05-hermes-pxSource advisory - PyPI
- Critical31 Mar 20264 packages tracked
Axios npm compromise (North Korea-nexus RAT)
Lead-maintainer account compromised via social engineering. Two malicious axios releases pulled in plain-crypto-js, whose postinstall fetched a cross-platform RAT from sfrclak[.]com:8000. Microsoft + Google attribute to Sapphire Sleet / UNC1069 (North Korea-nexus). Live for ~3 hours; ~100M weekly downloads in scope.
npmAffected packages4 packages · 8 versions
- npm
@qqbrowser/openclaw-qbot0.0.130 - npm
@shadanai/openclaw2026.3.28-22026.3.28-32026.3.31-12026.3.31-2 - npm
axios1.14.10.30.4 - npm
plain-crypto-js4.2.1
npm-2026-03-axiosSource advisory - npm
- High31 Mar 20261 package tracked
LofyGang returns with undicy-http typosquat delivering dual-payload RAT
JFrog tied `undicy-http@2.0.0` (a typosquat of `undici`) to the Brazil-based LofyGang group last seen in 2022. The package pairs a Node.js WebSocket RAT with a native `chromelevator.exe` binary that uses direct syscalls for process hollowing, then injects browser credential stealers targeting 50+ browsers and 90+ wallet extensions.
npmAffected packages1 package · 1 version
- npm
undicy-http2.0.0
npm-2026-03-31-undicy-lofygangSource advisory - npm
- Critical27 Mar 20261 package tracked
Telnyx Python SDK hides credential stealer in WAV-file steganography
TeamPCP published malicious `telnyx` 4.87.1 and 4.87.2 to PyPI on 27 March 2026 (~670k monthly downloads). Trojanised `_client.py` downloads steganographic payloads disguised as `.wav` files over plaintext HTTP, extracts the credential stealer, and persists. Windows variant drops `msbuild.exe` to the Startup folder; Linux variant uses a user-level systemd service. AES-256-CBC + RSA-4096 envelope for exfil.
PyPIAffected packages1 package · 2 versions
- PyPI
telnyx4.87.14.87.2
pypi-2026-03-27-telnyx-teampcpSource advisory - PyPI
- Critical24 Mar 20261 package tracked
LiteLLM PyPI backdoored as TeamPCP cascade reaches Python
TeamPCP used credentials harvested from the Trivy compromise to publish trojanised `litellm` 1.82.7 and 1.82.8 to PyPI on 24 March 2026 (~10:39 and 10:52 UTC). Malicious wheels drop a `litellm_init.pth` file in site-packages, executing a credential stealer at every Python interpreter start. PyPI quarantined the packages ~40 minutes after publication. Attackers later claimed ~500,000 credentials from this single compromise. LiteLLM averages ~3M daily downloads and ships in ~36% of cloud environments.
PyPIAffected packages1 package · 2 versions
- PyPI
litellm1.82.71.82.8
pypi-2026-03-24-litellm-teampcpSource advisory - PyPI
- High24 Mar 20265 packages tracked
5 npm typosquats target Solana + Ethereum dev libraries, exfil keys to Telegram
npm publisher `galedonovan` shipped five typosquats of legitimate crypto libraries. Each transparently intercepts private keys passed through normal API calls (Base58 decoding for Solana, Wallet construction for Ethereum), exfiltrates them to a hardcoded Telegram bot, then returns the expected result so functionality looks normal.
npmAffected packages5 packages · 4 versions
- npm
base_xd - npm
base-x-640.0.6 - npm
bs58-basic6.0.1 - npm
ethersproject-wallet5.8.1 - npm
raydium-bs581.9.7
npm-2026-03-24-solana-ethereum-typosquatsSource advisory - npm
- High23 Mar 20262 packages tracked
Checkmarx KICS GitHub Actions trojanised by TeamPCP
Between 12:58 and 16:50 UTC on 23 March 2026, TeamPCP hijacked 35 tags in the Checkmarx `ast-github-action` and `kics-github-action` repos to push a credential stealer, leveraging tokens stolen from the Trivy compromise. CI/CD pipelines using either Action during the window executed the stealer before the legitimate scan.
GitHub ActionsAffected packages2 packages · 0 versions
- GitHub Actions
checkmarx/ast-github-action - GitHub Actions
checkmarx/kics-github-action
github-actions-2026-03-23-checkmarx-kicsSource advisory - GitHub Actions
- Critical20 Mar 202629 packages tracked
CanisterWorm: @emilgroup and @teale.io npm publisher compromise (29+ packages)
An attacker compromised the @emilgroup and @teale.io npm namespaces, replacing 58 package-versions with a Python backdoor that polls an Internet Computer Protocol (ICP) canister for follow-on payloads. The implant persists via user-level systemd and includes worm-style republishing via deploy.js. Wiz later linked the tradecraft to TeamPCP; Socket declined firm attribution.
npmAffected packages29 packages · 58 versions
- npm
@emilgroup/account-sdk1.41.11.41.2 - npm
@emilgroup/account-sdk-node1.40.11.40.2 - npm
@emilgroup/accounting-sdk-node1.26.11.26.2 - npm
@emilgroup/api-documentation1.19.11.19.2 - npm
@emilgroup/auth-sdk1.25.11.25.2 - npm
@emilgroup/auth-sdk-node1.21.11.21.2 - npm
@emilgroup/billing-sdk1.56.11.56.2 - npm
@emilgroup/billing-sdk-node1.57.11.57.2 - npm
@emilgroup/claim-sdk1.41.11.41.2 - npm
@emilgroup/claim-sdk-node1.39.11.39.2 - npm
@emilgroup/customer-sdk1.54.11.54.2 - npm
@emilgroup/customer-sdk-node1.55.11.55.2 - npm
@emilgroup/document-sdk1.45.11.45.2 - npm
@emilgroup/document-sdk-node1.43.11.43.2 - npm
@emilgroup/gdv-sdk2.6.12.6.2 - npm
@emilgroup/insurance-sdk1.97.11.97.2 - npm
@emilgroup/insurance-sdk-node1.95.11.95.2 - npm
@emilgroup/notification-sdk-node1.4.11.4.2 - npm
@emilgroup/partner-portal-sdk-node1.1.11.1.2 - npm
@emilgroup/partner-sdk-node1.19.11.19.2 - npm
@emilgroup/payment-sdk1.15.11.15.2 - npm
@emilgroup/payment-sdk-node1.23.11.23.2 - npm
@emilgroup/process-manager-sdk-node1.13.11.13.2 - npm
@emilgroup/public-api-sdk1.33.11.33.2 - npm
@emilgroup/public-api-sdk-node1.35.11.35.2 - npm
@emilgroup/tenant-sdk1.34.11.34.2 - npm
@emilgroup/tenant-sdk-node1.33.11.33.2 - npm
@emilgroup/translation-sdk-node1.1.11.1.2 - npm
@teale.io/eslint-config1.8.91.8.10
npm-2026-03-20-canisterworm-emilgroup-tealeSource advisory - npm
- Critical19 Mar 20263 packages tracked
Trivy GitHub Action + Docker images compromised — start of TeamPCP cascade
Aqua Security's Trivy scanner was compromised on 19 March 2026 by the threat actor self-identifying as TeamPCP. The attacker force-pushed 76 of 77 tags in `aquasecurity/trivy-action` (only @0.35.0 survived) and all 7 tags in `aquasecurity/setup-trivy` to malicious commits, then published trojanised Trivy binary 0.69.4 + Docker images 0.69.5/0.69.6/latest. A stolen Argon-DevOps-Mgt service-account token seeded the downstream LiteLLM, Telnyx, Bitwarden CLI, and Checkmarx compromises.
DockerGitHub ActionsAffected packages3 packages · 4 versions
- Docker
aquasec/trivy0.69.40.69.50.69.6latest - GitHub Actions
aquasecurity/setup-trivy - GitHub Actions
aquasecurity/trivy-action
github-actions-2026-03-19-trivy-teampcp-cascadeSource advisory - Docker
- High18 Mar 20262 packages tracked
GlassWorm sleeper extensions activate on Open VSX
Roughly 40 malicious VS Code extensions surfaced March 14-18, 2026: 20+ new extensions, ~20 previously dormant sleepers activated, plus 11 extensionPack droppers. The campaign hosts VSIX payloads on attacker-controlled GitHub releases to evade registry takedowns. Publishing accounts: `laura6909`, `martina0094`, `chiara585`, `francesca898`.
Open VSXAffected packages2 packages · 3 versions
- Open VSX
96-studio.json-formatter0.0.20.0.4 - Open VSX
lauracode.wrap-selected-code0.0.2
openvsx-2026-03-18-glassworm-sleeperSource advisory - Open VSX
- High13 Mar 2026Feed-only · no version-specific detection
GlassWorm: 72+ Open VSX extensions weaponised via transitive loaders
Socket linked at least 72 additional malicious Open VSX extensions to the GlassWorm campaign. Newer variants use `extensionPack` / `extensionDependencies` fields to transitively pull GlassWorm loaders rather than embedding malware directly. Obfuscation rotated to RC4 + base64 with keys delivered in HTTP response headers.
openvsx-2026-03-13-glassworm-transitiveSource advisory - Medium12 Mar 20266 packages tracked
6 malicious Packagist OphimCMS themes ship trojanised jQuery and FUNNULL redirects
Six Composer packages from the `ophimcms` organisation posed as OphimCMS themes containing trojanised jQuery. The payload exfiltrates URLs, injects ads, and redirects mobile traffic via OFAC-sanctioned FUNNULL infrastructure. Combined ~2,750 installs.
PackagistAffected packages6 packages · 6 versions
- Packagist
ophimcms/theme-dy1.0.0 - Packagist
ophimcms/theme-legend1.0.0 - Packagist
ophimcms/theme-motchill1.0.0 - Packagist
ophimcms/theme-mtyy1.0.0 - Packagist
ophimcms/theme-pcc1.2.2 - Packagist
ophimcms/theme-rrdyw1.0.0
packagist-2026-03-12-ophimcms-themesSource advisory - Packagist
- Medium28 Feb 20265 packages tracked
5 malicious Rust crates pose as time utilities to exfiltrate .env files
Five crates published between late February and early March 2026 posed as local time utilities while exfiltrating .env files via `curl` to a lookalike domain `timeapis.io` (typosquatting `timeapi.io`). All packages were 0.1.0 and yanked within hours. Account aliases: `gehakax777`, `dictorudin`.
crates.ioAffected packages5 packages · 5 versions
- crates.io
chrono_anchor0.1.0 - crates.io
dnp3times0.1.0 - crates.io
time_calibrator0.1.0 - crates.io
time_calibrators0.1.0 - crates.io
time-sync0.1.0
crates-2026-02-28-time-utility-typosquatsSource advisory - crates.io
- High27 Feb 202626 packages tracked
StegaBin: 26 npm typosquats use Pastebin steganography to deliver Contagious Interview RAT
Socket disclosed 26 typosquatted npm packages tied to North Korea's Contagious Interview / FAMOUS CHOLLIMA cluster. The loader decodes steganographically-encoded Pastebin URLs to resolve C2 hosted across 31 Vercel deployments, then retrieves a 9-module infostealer and RAT toolkit.
npmAffected packages26 packages · 26 versions
- npm
argonist0.41.0 - npm
bcryptance6.5.2 - npm
bee-quarl2.1.2 - npm
bubble-core6.26.2 - npm
corstoken2.14.7 - npm
daytonjs1.11.20 - npm
ether-lint5.9.4 - npm
expressjs-lint5.3.2 - npm
fastify-lint5.8.0 - npm
formmiderable3.5.7 - npm
hapi-lint19.1.2 - npm
iosysredis5.13.2 - npm
jslint-config10.22.2 - npm
jsnwebapptoken8.40.2 - npm
kafkajs-lint2.21.3 - npm
loadash-lint4.17.24 - npm
mqttoken5.40.2 - npm
prism-lint7.4.2 - npm
promanage6.0.21 - npm
sequelization6.40.2 - npm
typoriem0.4.17 - npm
undicy-lint7.23.1 - npm
uuindex13.1.0 - npm
vitetest-lint4.1.21 - npm
windowston3.19.2 - npm
zoddle4.4.2
npm-2026-02-27-stegabin-contagious-interviewSource advisory - npm
- Critical20 Feb 202619 packages tracked
SANDWORM_MODE: 19 npm typosquats with self-spreading worm + AI toolchain poisoning
Socket disclosed a Shai-Hulud-style self-propagating worm spread across at least 19 typosquatted npm packages from accounts `official334` and `javaorg`. It harvests CI secrets and crypto keys, propagates via stolen npm/GitHub tokens, and injects prompt-injection logic into MCP servers used by AI coding assistants.
npmAffected packages19 packages · 19 versions
- npm
claud-code0.2.1 - npm
cloude0.3.0 - npm
cloude-code0.2.1 - npm
crypto-locale1.0.0 - npm
crypto-reader-info1.0.0 - npm
detect-cache1.0.0 - npm
format-defaults1.0.0 - npm
hardhta1.0.0 - npm
locale-loader-pro1.0.0 - npm
naniod1.0.0 - npm
node-native-bridge1.0.0 - npm
opencraw2026.2.17 - npm
parse-compat1.0.0 - npm
rimarf1.0.0 - npm
scan-store1.0.0 - npm
secp2561.0.0 - npm
suport-color1.0.1 - npm
veim2.46.2 - npm
yarsg18.0.1
npm-2026-02-20-sandworm-modeSource advisory - npm
- High17 Feb 20261 package tracked
cline npm package hijacked via "Clinejection" prompt-injection chain
An attacker abused an unsanitised AI issue-triage GitHub Actions workflow on the Cline repo to poison the release pipeline cache and steal the npm publish token. They published `cline@2.3.0` with a postinstall script that globally installed the second-stage package `openclaw`. ~90k weekly downloads; live for ~8 hours before Cline rotated the token and shipped 2.4.0.
npmAffected packages1 package · 1 version
- npm
cline2.3.0
npm-2026-02-17-cline-clinejectionSource advisory - npm
- High11 Feb 202630 packages tracked
Lazarus "graphalgo" fake-recruiter campaign (npm + PyPI)
ReversingLabs attributed an ongoing fake-recruiter campaign (active since May 2025, reported Feb 2026) to North Korea's Lazarus Group (overlapping Jade Sleet / UNC4899). Crypto, JavaScript, and Python developers are lured via LinkedIn/Reddit/Facebook into interview "coding tasks" that pull a token-protected RAT loader from npm and PyPI. ~192 malicious packages attributed in total; bigmathutils alone passed 10,000 downloads.
npmPyPIAffected packages30 packages · 44 versions
- npm
bigmathex - npm
bigmathix - npm
bigmathlib - npm
bigmathutils1.0.01.1.0 - npm
bignumberx - npm
bignumex - npm
bignumx - PyPI
bigpyx - npm
graphalgo2.2.5-pre2.2.62.2.72.2.82.2.92.2.102.2.11 - PyPI
graphalgo-py3.5.1rc0.dev03.5.23.5.33.5.53.5.6 - npm
graphchain - PyPI
graphdict - PyPI
graphex3.5.73.5.83.5.93.5.10 - npm
graphflowx - npm
graphflux - npm
graphhub - npm
graphkitx - npm
graphlibcore2.2.62.2.72.2.82.2.92.2.102.2.11 - PyPI
graphlibx - npm
graphnet - npm
graphnetworkx2.1.62.1.72.1.82.1.92.1.102.1.11 - PyPI
graphnode - npm
graphorbit - npm
graphorithm2.2.62.2.72.2.82.2.9 - npm
graphrix - npm
graphstruct2.2.62.2.72.2.8 - PyPI
graphsync - npm
netstruct2.1.62.1.8 - npm
terminal-kleur - npm
terminalcolor2562.0.22.0.32.1.02.2.02.2.6
multi-2026-02-11-lazarus-graphalgoSource advisory - npm
- Medium5 Feb 20263 packages tracked
Polymarket SDK typosquats on crates.io
Three crates impersonating `polymarket-client-sdk` were published between 5 and 19 February 2026 and exfiltrated local credential files. The malicious crates were yanked and publisher accounts disabled. Combined downloads stayed under 100, but targeting was high-value (Polymarket / Web3 developers).
crates.ioAffected packages3 packages · 0 versions
- crates.io
polymarket-client-sdks - crates.io
polymarket-clients-sdk - crates.io
polymarkets-client-sdk
crates-2026-02-05-polymarket-typosquatsSource advisory - crates.io
- Critical27 Jan 20262 packages tracked
dYdX v4-client npm + PyPI compromise (wallet stealer + RAT)
Maintainer credentials for the dYdX decentralized exchange were compromised; malicious versions of the official v4 client were pushed to npm and PyPI in a coordinated release. The npm payload exfiltrates wallet seed phrases through a malicious `createRegistry()` function. The PyPI variant additionally drops a Python RAT executed on import.
npmPyPIAffected packages2 packages · 6 versions
- npm
@dydxprotocol/v4-client-js1.0.311.15.21.22.13.4.1 - PyPI
dydx-v4-client1.1.5.post11.1.5post1
multi-2026-01-27-dydx-compromiseSource advisory - npm
- High17 Jan 20261 package tracked
sympy-dev PyPI typosquat delivering XMRig cryptominer
A PyPI typosquat of SymPy was published by the account "Nanit" across four versions on Jan 17, 2026. It fetches a remote JSON config, downloads an ELF, and executes it from a memfd to evade disk-based detection. The payload is XMRig mining Monero on infected developer workstations.
PyPIAffected packages1 package · 4 versions
- PyPI
sympy-dev1.2.31.2.41.2.51.2.6
pypi-2026-01-17-sympy-dev-minerSource advisory - PyPI
- Critical15 Sept 2025197 packages tracked
Original Shai-Hulud npm worm
First successful self-propagating worm in the npm ecosystem. Downstream of the August 2025 s1ngularity/Nx GitHub-token theft. The postinstall hook ran TruffleHog to harvest secrets, opened public GitHub repos named "Shai-Hulud" to publish them, force-converted private repos to public with a "-migration" suffix, and used stolen npm tokens to publish malicious versions of any package the maintainer could access. ~180 unique packages compromised across 300+ versions, including CrowdStrike's own scope (@crowdstrike/*).
npmAffected packages197 packages · 509 versions
- npm
@ahmedhfarag/ngx-perfect-scrollbar20.0.20 - npm
@ahmedhfarag/ngx-virtual-scroller4.0.4 - npm
@art-ws/common2.0.28 - npm
@art-ws/config-eslint2.0.42.0.5 - npm
@art-ws/config-ts2.0.72.0.8 - npm
@art-ws/db-context2.0.24 - npm
@art-ws/di2.0.282.0.32 - npm
@art-ws/di-node2.0.13 - npm
@art-ws/eslint1.0.51.0.6 - npm
@art-ws/fastify-http-server2.0.242.0.27 - npm
@art-ws/http-server2.0.212.0.25 - npm
@art-ws/openapi0.1.90.1.12 - npm
@art-ws/package-base1.0.51.0.6 - npm
@art-ws/prettier1.0.51.0.6 - npm
@art-ws/slf2.0.152.0.22 - npm
@art-ws/ssl-info1.0.91.0.10 - npm
@art-ws/web-app1.0.31.0.4 - npm
@basic-ui-components-stc/basic-ui-components1.0.5 - npm
@crowdstrike/commitlint8.1.18.1.2 - npm
@crowdstrike/falcon-shoelace0.4.10.4.2 - npm
@crowdstrike/foundry-js0.19.10.19.2 - npm
@crowdstrike/glide-core0.34.20.34.3 - npm
@crowdstrike/logscale-dashboard1.205.11.205.2 - npm
@crowdstrike/logscale-file-editor1.205.11.205.2 - npm
@crowdstrike/logscale-parser-edit1.205.11.205.2 - npm
@crowdstrike/logscale-search1.205.11.205.2 - npm
@crowdstrike/tailwind-toucan-base5.0.15.0.2 - npm
@ctrl/deluge7.2.17.2.2 - npm
@ctrl/golang-template1.4.21.4.3 - npm
@ctrl/magnet-link4.0.34.0.4 - npm
@ctrl/ngx-codemirror7.0.17.0.2 - npm
@ctrl/ngx-csv6.0.16.0.2 - npm
@ctrl/ngx-emoji-mart9.2.19.2.2 - npm
@ctrl/ngx-rightclick4.0.14.0.2 - npm
@ctrl/qbittorrent9.7.19.7.2 - npm
@ctrl/react-adsense2.0.12.0.2 - npm
@ctrl/shared-torrent6.3.16.3.2 - npm
@ctrl/tinycolor4.1.14.1.2 - npm
@ctrl/torrent-file4.1.14.1.2 - npm
@ctrl/transmission7.3.1 - npm
@ctrl/ts-base324.0.14.0.2 - npm
@hestjs/core0.2.1 - npm
@hestjs/cqrs0.1.6 - npm
@hestjs/demo0.1.2 - npm
@hestjs/eslint-config0.1.2 - npm
@hestjs/logger0.1.6 - npm
@hestjs/scalar0.1.7 - npm
@hestjs/validation0.1.6 - npm
@nativescript-community/arraybuffers1.1.61.1.71.1.8 - npm
@nativescript-community/gesturehandler2.0.35 - npm
@nativescript-community/perms3.0.53.0.63.0.73.0.83.0.9 - npm
@nativescript-community/sentry4.6.43 - npm
@nativescript-community/sqlite3.5.23.5.33.5.43.5.5 - npm
@nativescript-community/text1.6.91.6.101.6.111.6.121.6.13 - npm
@nativescript-community/typeorm0.2.300.2.310.2.320.2.33 - npm
@nativescript-community/ui-collectionview6.0.6 - npm
@nativescript-community/ui-document-picker1.1.271.1.2813.0.32 - npm
@nativescript-community/ui-drawer0.1.30 - npm
@nativescript-community/ui-image4.5.6 - npm
@nativescript-community/ui-label1.3.351.3.361.3.37 - npm
@nativescript-community/ui-material-bottom-navigation7.2.727.2.737.2.747.2.75 - npm
@nativescript-community/ui-material-bottomsheet7.2.72 - npm
@nativescript-community/ui-material-core7.2.727.2.737.2.747.2.757.2.76 - npm
@nativescript-community/ui-material-core-tabs7.2.727.2.737.2.747.2.757.2.76 - npm
@nativescript-community/ui-material-ripple7.2.727.2.737.2.747.2.75 - npm
@nativescript-community/ui-material-tabs7.2.727.2.737.2.747.2.75 - npm
@nativescript-community/ui-pager14.1.3614.1.3714.1.38 - npm
@nativescript-community/ui-pulltorefresh2.5.42.5.52.5.62.5.7 - npm
@nexe/config-manager0.1.1 - npm
@nexe/eslint-config0.1.1 - npm
@nexe/logger0.1.3 - npm
@nstudio/angular20.0.420.0.520.0.6 - npm
@nstudio/focus20.0.420.0.520.0.6 - npm
@nstudio/nativescript-checkbox2.0.62.0.72.0.82.0.9 - npm
@nstudio/nativescript-loading-indicator5.0.15.0.25.0.35.0.4 - npm
@nstudio/ui-collectionview5.1.115.1.125.1.135.1.14 - npm
@nstudio/web20.0.4 - npm
@nstudio/web-angular20.0.4 - npm
@nstudio/xplat20.0.520.0.620.0.7 - npm
@nstudio/xplat-utils20.0.520.0.620.0.7 - npm
@operato/board9.0.369.0.379.0.389.0.399.0.409.0.419.0.429.0.439.0.449.0.459.0.46 - npm
@operato/data-grist9.0.299.0.359.0.369.0.37 - npm
@operato/graphql9.0.229.0.359.0.369.0.379.0.389.0.399.0.409.0.419.0.429.0.439.0.449.0.459.0.46 - npm
@operato/headroom9.0.29.0.359.0.369.0.37 - npm
@operato/help9.0.359.0.369.0.379.0.389.0.399.0.409.0.419.0.429.0.439.0.449.0.459.0.46 - npm
@operato/i18n9.0.359.0.369.0.37 - npm
@operato/input9.0.279.0.359.0.369.0.379.0.389.0.399.0.409.0.419.0.429.0.439.0.449.0.459.0.469.0.479.0.48 - npm
@operato/layout9.0.359.0.369.0.37 - npm
@operato/popup9.0.229.0.359.0.369.0.379.0.389.0.399.0.409.0.419.0.429.0.439.0.449.0.459.0.469.0.49 - npm
@operato/pull-to-refresh9.0.369.0.379.0.389.0.399.0.409.0.419.0.42 - npm
@operato/shell9.0.229.0.359.0.369.0.379.0.389.0.39 - npm
@operato/styles9.0.29.0.359.0.369.0.37 - npm
@operato/utils9.0.229.0.359.0.369.0.379.0.389.0.399.0.409.0.419.0.429.0.439.0.449.0.459.0.469.0.49 - npm
@teselagen/bio-parsers0.4.290.4.30 - npm
@teselagen/bounce-loader0.3.160.3.17 - npm
@teselagen/file-utils0.3.210.3.22 - npm
@teselagen/liquibase-tools0.4.1 - npm
@teselagen/ove0.7.390.7.40 - npm
@teselagen/range-utils0.3.140.3.15 - npm
@teselagen/react-list0.8.190.8.20 - npm
@teselagen/react-table6.10.196.10.206.10.216.10.22 - npm
@teselagen/sequence-utils0.3.330.3.34 - npm
@teselagen/ui0.9.90.9.10 - npm
@thangved/callback-window1.1.4 - npm
@things-factory/attachment-base9.0.429.0.439.0.449.0.459.0.469.0.479.0.489.0.499.0.509.0.519.0.529.0.539.0.549.0.55 - npm
@things-factory/auth-base9.0.429.0.439.0.449.0.45 - npm
@things-factory/email-base9.0.429.0.439.0.449.0.459.0.469.0.479.0.489.0.499.0.509.0.519.0.529.0.539.0.549.0.559.0.569.0.579.0.589.0.59 - npm
@things-factory/env9.0.429.0.439.0.449.0.45 - npm
@things-factory/integration-base9.0.429.0.439.0.449.0.45 - npm
@things-factory/integration-marketplace9.0.429.0.439.0.449.0.45 - npm
@things-factory/shell9.0.429.0.439.0.449.0.45 - npm
@tnf-dev/api1.0.8 - npm
@tnf-dev/core1.0.8 - npm
@tnf-dev/js1.0.8 - npm
@tnf-dev/mui1.0.8 - npm
@tnf-dev/react1.0.8 - npm
@ui-ux-gang/devextreme-angular-rpk24.1.7 - npm
@yoobic/design-system6.5.17 - npm
@yoobic/jpeg-camera-es61.0.13 - npm
@yoobic/yobi8.7.53 - npm
airchief0.3.1 - npm
airpilot0.8.8 - npm
angulartics214.1.114.1.2 - npm
browser-webdriver-downloader3.0.8 - npm
capacitor-notificationhandler0.0.20.0.3 - npm
capacitor-plugin-healthapp0.0.20.0.3 - npm
capacitor-plugin-ihealth1.1.81.1.9 - npm
capacitor-plugin-vonage1.0.21.0.3 - npm
capacitorandroidpermissions0.0.40.0.5 - npm
config-cordova0.8.5 - npm
cordova-plugin-voxeet21.0.24 - npm
cordova-voxeet1.0.32 - npm
create-hest-app0.1.9 - npm
db-evo1.1.41.1.5 - npm
devextreme-angular-rpk21.2.8 - npm
devextreme-rpk21.2.8 - npm
ember-browser-services5.0.25.0.3 - npm
ember-headless-form1.1.21.1.3 - npm
ember-headless-form-yup1.0.1 - npm
ember-headless-table2.1.52.1.6 - npm
ember-url-hash-polyfill1.0.121.0.13 - npm
ember-velcro2.2.12.2.2 - npm
encounter-playground0.0.20.0.30.0.40.0.5 - npm
eslint-config-crowdstrike11.0.211.0.3 - npm
eslint-config-crowdstrike-node4.0.34.0.4 - npm
eslint-config-teselagen6.1.76.1.8 - npm
globalize-rpk1.7.4 - npm
graphql-sequelize-teselagen5.3.85.3.9 - npm
html-to-base64-image1.0.2 - npm
json-rules-engine-simplified0.2.10.2.30.2.4 - npm
jumpgate0.0.2 - npm
koa2-swagger-ui5.11.15.11.2 - npm
mcfly-semantic-release1.3.1 - npm
mcp-knowledge-base0.0.2 - npm
mcp-knowledge-graph1.2.1 - npm
mobioffice-cli1.0.3 - npm
monorepo-next13.0.113.0.2 - npm
mstate-angular0.4.4 - npm
mstate-cli0.4.7 - npm
mstate-dev-react1.1.1 - npm
mstate-react1.6.5 - npm
ng2-file-upload7.0.27.0.38.0.18.0.28.0.39.0.1 - npm
ngx-bootstrap18.1.419.0.319.0.420.0.320.0.420.0.520.0.6 - npm
ngx-color10.0.110.0.2 - npm
ngx-toastr19.0.119.0.2 - npm
ngx-trend8.0.1 - npm
ngx-ws1.1.51.1.6 - npm
oradm-to-gql35.0.1435.0.15 - npm
oradm-to-sqlz1.1.21.1.4 - npm
ove-auto-annotate0.0.90.0.10 - npm
pm2-gelf-json1.0.41.0.5 - npm
printjs-rpk1.6.1 - npm
react-complaint-image0.0.320.0.340.0.35 - npm
react-jsonschema-form-conditionals0.3.180.3.200.3.21 - npm
react-jsonschema-form-extras1.0.31.0.4 - npm
react-jsonschema-rxnt-extras0.4.80.4.9 - npm
remark-preset-lint-crowdstrike4.0.14.0.2 - npm
rxnt-authentication0.0.30.0.40.0.50.0.6 - npm
rxnt-healthchecks-nestjs1.0.21.0.31.0.41.0.5 - npm
rxnt-kue1.0.41.0.51.0.61.0.7 - npm
swc-plugin-component-annotate1.9.11.9.2 - npm
tbssnch1.0.2 - npm
teselagen-interval-tree1.1.2 - npm
tg-client-query-builder2.14.42.14.5 - npm
tg-redbird1.3.11.3.2 - npm
tg-seq-gen1.0.91.0.10 - npm
thangved-react-grid1.0.3 - npm
ts-gaussian3.0.53.0.6 - npm
ts-imports1.0.11.0.2 - npm
tvi-cli0.1.5 - npm
ve-bamreader0.2.60.2.7 - npm
ve-editor1.0.11.0.2 - npm
verror-extra6.0.1 - npm
voip-callkit1.0.21.0.3 - npm
wdio-web-reporter0.1.3 - npm
yargs-help-output5.0.3 - npm
yoo-styles6.0.326
npm-2025-09-shai-hulud-originalSource advisory - npm
Sources cited per card. We only list package versions named by the original advisory; we don't infer compromises. Missing something? Send it in.