← All packages

Supply-chain attacks we’ve detected

Popular npm packages whose release stream was tampered with — either a version OSV confirmed as malicious code, or a version our own analysis flagged as a likely account takeover before any public advisory. None of these versions were ever served from this registry; where the package still has clean releases, those keep flowing.

200
Packages hit
300
Blocked versions
73
Confirmed malware (OSV)
127
Detected before any advisory

Show OSV-confirmed only · updated

Confirmed malicious releases

Versions OSV’s malicious-packages dataset confirms contained malicious code. We blocked these the moment the advisory landed — or before, then OSV agreed.

fsevents Malicious code clean versions still served
32,732,849 weekly downloads

MAL-2023-462 Malicious code in fsevents (npm)

Native Access to MacOS FSEvents

First detected ·  most recent
fs Malicious code clean versions still served
1,848,666 weekly downloads

MAL-2025-21003 Malicious code in fs (npm)

This package name is not currently in use, but was formerly occupied by another package. To avoid malicious use, npm is hanging on to the package name, but loosely, and we'll probably give it to you if you want it.

Blocked 2 versions: 0.0.2 0.0.0
First detected ·  most recent
@bitwarden/cli Malicious code clean versions still served
95,180 weekly downloads

MAL-2026-3020 Malicious code in @bitwarden/cli (npm)

A secure and free password manager for all of your devices.

Blocked 1 version: 2026.4.0
detected
@antv/l7 Malicious code clean versions still served
45,765 weekly downloads

MAL-2026-4033 Malicious code in @antv/l7 (npm)

Blocked 2 versions: 2.27.10 2.26.10
First detected ·  most recent
@antv/l7-maps Malicious code clean versions still served
44,717 weekly downloads

MAL-2026-4045 Malicious code in @antv/l7-maps (npm)

Blocked 2 versions: 2.27.10 2.26.10
First detected ·  most recent
@pisell/pisellos Malicious code clean versions still served
5,030 weekly downloads

MAL-2026-4417 Malicious code in @pisell/pisellos (npm)

一个可扩展的前端模块化SDK框架,支持插件系统

Blocked 1 version: 2.2.172
detected
@ensdomains/ens-contracts Malicious code
4,205 weekly downloads

MAL-2025-190931 Malicious code in @ensdomains/ens-contracts (npm)

Blocked 1 version: 1.7.0
detected
@onerjs/addons Malicious code clean versions still served
1,481 weekly downloads

MAL-2026-4410 Malicious code in @onerjs/addons (npm)

Blocked 1 version: 8.52.3
detected
764 weekly downloads

MAL-2026-2055 Malicious code in @emilgroup/partner-sdk-node (npm)

OpenAPI client for @emilgroup/partner-sdk-node

First detected ·  most recent
frank-bot-gogle-cloning Malicious code
480 weekly downloads

MAL-2026-3080 Malicious code in frank-bot-gogle-cloning (npm)

Security audit module

Blocked 1 version: 1.1.0
detected
@antv/gpt-vis-ssr Malicious code clean versions still served
458 weekly downloads

MAL-2026-4021 Malicious code in @antv/gpt-vis-ssr (npm)

SSR(Server Side Render) for AntV GPT-Vis.

Blocked 1 version: 0.5.7
detected
@emilgroup/task-sdk-node Malicious code clean versions still served
415 weekly downloads

MAL-2026-2079 Malicious code in @emilgroup/task-sdk-node (npm)

OpenAPI client for @emilgroup/task-sdk-node

Blocked 2 versions: 1.0.3 1.0.2
First detected ·  most recent
@emilgroup/task-sdk Malicious code clean versions still served
296 weekly downloads

MAL-2026-2078 Malicious code in @emilgroup/task-sdk (npm)

OpenAPI client for @emilgroup/task-sdk

Blocked 1 version: 1.0.2
detected
@clearpool/table Malicious code
258 weekly downloads

MAL-2026-3058 Malicious code in @clearpool/table (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 9.9.9
First detected ·  most recent
@clearpool/streaming Malicious code
255 weekly downloads

MAL-2026-3057 Malicious code in @clearpool/streaming (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 9.9.9
First detected ·  most recent
@clearpool/utils Malicious code
251 weekly downloads

MAL-2026-3059 Malicious code in @clearpool/utils (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 9.9.9
First detected ·  most recent
@clearpool/comms Malicious code
213 weekly downloads

MAL-2026-3056 Malicious code in @clearpool/comms (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 9.9.9
First detected ·  most recent
frank-research-poc-apple Malicious code
213 weekly downloads

MAL-2026-3081 Malicious code in frank-research-poc-apple (npm)

Blocked 1 version: 1.1.4
detected
uipath-ui-widgets Malicious code
213 weekly downloads

MAL-2026-3036 Malicious code in uipath-ui-widgets (npm)

Blocked 1 version: 1.0.1
detected
rtms-manager Malicious code
207 weekly downloads

MAL-2026-2862 Malicious code in rtms-manager (npm)

Dependency Confusion poc

Blocked 2 versions: 1.4.0 1.2.0
First detected ·  most recent
standalone-apps Malicious code
205 weekly downloads

MAL-2026-3037 Malicious code in standalone-apps (npm)

Blocked 1 version: 1.0.1
detected
react-dnd-14 Malicious code
194 weekly downloads

MAL-2026-3196 Malicious code in react-dnd-14 (npm)

Blocked 1 version: 99.9.1
detected
wm-plugin-teach-me-widget Malicious code
181 weekly downloads

MAL-2026-3128 Malicious code in wm-plugin-teach-me-widget (npm)

Security testing test package

Blocked 1 version: 21.0.31
detected
apollo-landing Malicious code
156 weekly downloads

MAL-2026-3038 Malicious code in apollo-landing (npm)

Blocked 1 version: 1.0.1
detected
apollo-vertex Malicious code
154 weekly downloads

MAL-2026-3040 Malicious code in apollo-vertex (npm)

Blocked 1 version: 1.0.1
detected
process-app-task Malicious code
152 weekly downloads

MAL-2026-3039 Malicious code in process-app-task (npm)

Blocked 1 version: 1.0.1
detected
axis-abc-search-address Malicious code
148 weekly downloads

MAL-2026-3076 Malicious code in axis-abc-search-address (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
axis-abc-portal-menu Malicious code
148 weekly downloads

MAL-2026-3074 Malicious code in axis-abc-portal-menu (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
apcyber-test-package Malicious code
143 weekly downloads

MAL-2026-3304 Malicious code in apcyber-test-package (npm)

Internal automation library.

Blocked 2 versions: 100.0.0 99.99.99
First detected ·  most recent
axis-abc-search-account Malicious code
139 weekly downloads

MAL-2026-3075 Malicious code in axis-abc-search-account (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
path-internal-util Malicious code
137 weekly downloads

MAL-2026-3312 Malicious code in path-internal-util (npm)

Node.js path module

Blocked 1 version: 1.0.1
detected
@activation_code/activate Malicious code
72 weekly downloads

MAL-2026-3106 Malicious code in @activation_code/activate (npm)

activate utilities

Blocked 1 version: 99.0.3
detected
tether-base Malicious code
64 weekly downloads

MAL-2026-3033 Malicious code in tether-base (npm)

Test package for dependency confusion detection

Blocked 1 version: 99.0.0
detected
@alfa.life.mapp/app.web Malicious code
37 weekly downloads

MAL-2026-3052 Malicious code in @alfa.life.mapp/app.web (npm)

app.web utilities

Blocked 3 versions: 99.0.18 99.0.16 99.0.15
First detected ·  most recent
30 weekly downloads

MAL-2026-3053 Malicious code in @apple-pay-trust/merchant-session (npm)

merchant-session utilities

Blocked 2 versions: 99.0.3 99.0.1
First detected ·  most recent
28 weekly downloads

MAL-2026-3111 Malicious code in @apple-pay-trust/authorize-payment (npm)

authorize-payment utilities

Blocked 1 version: 99.0.3
detected
@apiary-annex/title Malicious code
28 weekly downloads

MAL-2026-3110 Malicious code in @apiary-annex/title (npm)

title utilities

Blocked 1 version: 99.0.3
detected
@apiary-annex/meta Malicious code
28 weekly downloads

MAL-2026-3109 Malicious code in @apiary-annex/meta (npm)

meta utilities

Blocked 1 version: 99.0.3
detected
27 weekly downloads

MAL-2026-3112 Malicious code in @apple-pay-trust/cancelled (npm)

cancelled utilities

Blocked 2 versions: 99.0.4 99.0.3
First detected ·  most recent
26 weekly downloads

MAL-2026-3113 Malicious code in @apple-pay-trust/check-apple-pay-result (npm)

check-apple-pay-result utilities

Blocked 1 version: 99.0.3
detected
@apple-pay-trust/start Malicious code
25 weekly downloads

MAL-2026-3054 Malicious code in @apple-pay-trust/start (npm)

start utilities

Blocked 3 versions: 99.0.4 99.0.3 99.0.1
First detected ·  most recent
23 weekly downloads

MAL-2026-3116 Malicious code in @business_promocode/apply_promocode (npm)

apply_promocode utilities

Blocked 1 version: 99.0.3
detected
22 weekly downloads

MAL-2026-3115 Malicious code in @b2b_blocker/show_activation_error (npm)

show_activation_error utilities

Blocked 2 versions: 99.0.4 99.0.3
First detected ·  most recent
20 weekly downloads

MAL-2026-3117 Malicious code in @business_promocode/cancel_promocode (npm)

cancel_promocode utilities

Blocked 1 version: 99.0.3
detected
@ozon-complt/split Malicious code
19 weekly downloads

MAL-2026-3067 Malicious code in @ozon-complt/split (npm)

split utilities

Blocked 2 versions: 99.0.4 99.0.2
First detected ·  most recent
@voiceflow/google-types Malicious code
19 weekly downloads

MAL-2025-191352 Malicious code in @voiceflow/google-types (npm)

Google service types

Blocked 1 version: 2.21.14
detected
18 weekly downloads

MAL-2026-3061 Malicious code in @google-pay-trust/authorize-payment (npm)

authorize-payment utilities

Blocked 3 versions: 99.0.4 99.0.3 99.0.1
First detected ·  most recent
axis-charts Malicious code
18 weekly downloads

MAL-2026-3077 Malicious code in axis-charts (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
17 weekly downloads

MAL-2026-3066 Malicious code in @ozon-complt/antibot-handler (npm)

antibot-handler utilities

Blocked 3 versions: 99.0.4 99.0.2 99.0.1
First detected ·  most recent
17 weekly downloads

MAL-2026-3064 Malicious code in @google-pay-trust/init-google-pay (npm)

init-google-pay utilities

Blocked 2 versions: 99.0.2 99.0.1
First detected ·  most recent
axis-notification Malicious code
17 weekly downloads

MAL-2026-3078 Malicious code in axis-notification (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
axis-ui-generator Malicious code
17 weekly downloads

MAL-2026-3079 Malicious code in axis-ui-generator (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
17 weekly downloads

MAL-2026-3062 Malicious code in @google-pay-trust/cancelled (npm)

cancelled utilities

Blocked 1 version: 99.0.1
detected
@apple-pay-trust/finish Malicious code
16 weekly downloads

MAL-2026-3114 Malicious code in @apple-pay-trust/finish (npm)

finish utilities

Blocked 2 versions: 99.0.4 99.0.3
First detected ·  most recent
16 weekly downloads

MAL-2026-3055 Malicious code in @apple-pay-trust/validate-merchant (npm)

validate-merchant utilities

Blocked 3 versions: 99.0.4 99.0.3 99.0.1
First detected ·  most recent
@w3m-frame/session_update Malicious code
16 weekly downloads

MAL-2026-3122 Malicious code in @w3m-frame/session_update (npm)

session_update utilities

Blocked 1 version: 99.0.4
detected
@tw-utils/static Malicious code
15 weekly downloads

MAL-2026-3073 Malicious code in @tw-utils/static (npm)

static utilities

Blocked 4 versions: 99.0.4 99.0.3 99.0.2 99.0.1
First detected ·  most recent
@tw-marionette/input Malicious code
15 weekly downloads

MAL-2026-3071 Malicious code in @tw-marionette/input (npm)

input utilities

Blocked 3 versions: 99.0.4 99.0.2 99.0.1
First detected ·  most recent
@tw-models/storage Malicious code
14 weekly downloads

MAL-2026-3072 Malicious code in @tw-models/storage (npm)

storage utilities

Blocked 4 versions: 99.0.4 99.0.3 99.0.2 99.0.1
First detected ·  most recent
@apple-pay-trust/destroy Malicious code
14 weekly downloads

MAL-2026-3317 Malicious code in @apple-pay-trust/destroy (npm)

destroy utilities

Blocked 1 version: 99.0.4
detected
@google-pay-trust/finish Malicious code
14 weekly downloads

MAL-2026-3063 Malicious code in @google-pay-trust/finish (npm)

finish utilities

Blocked 1 version: 99.0.1
detected
@pyme-web/ui-base Malicious code
14 weekly downloads

MAL-2026-3118 Malicious code in @pyme-web/ui-base (npm)

ui-base utilities

Blocked 1 version: 99.0.4
detected
12 weekly downloads

MAL-2026-3068 Malicious code in @sbt_gitverse/analytics-client (npm)

analytics-client utilities

Blocked 4 versions: 99.0.7 99.0.5 99.0.4 99.0.3
First detected ·  most recent
apple-internal-pki-utils Malicious code
12 weekly downloads

MAL-2026-3160 Malicious code in apple-internal-pki-utils (npm)

Blocked 1 version: 1.0.1
detected
@pyme-web/web-api Malicious code
12 weekly downloads

MAL-2026-3120 Malicious code in @pyme-web/web-api (npm)

web-api utilities

Blocked 1 version: 99.0.4
detected
kl-b2c-ui-kit Malicious code
9 weekly downloads

MAL-2026-3082 Malicious code in kl-b2c-ui-kit (npm)

kl-b2c-ui-kit utilities

Blocked 3 versions: 99.0.4 99.0.2 99.0.1
First detected ·  most recent
@tochka-ui/foundation Malicious code
9 weekly downloads

MAL-2026-3069 Malicious code in @tochka-ui/foundation (npm)

gigaid utilities

Blocked 4 versions: 99.0.7 99.0.5 99.0.4 99.0.3
First detected ·  most recent
@pyme-web/ui-widget Malicious code
9 weekly downloads

MAL-2026-3119 Malicious code in @pyme-web/ui-widget (npm)

ui-widget utilities

Blocked 1 version: 99.0.4
detected
9 weekly downloads

MAL-2025-190901 Malicious code in @postman/final-node-keytar (npm)

Bindings to native Mac/Linux/Windows password APIs

Blocked 1 version: 7.9.0
detected
@tw-marionette/clipboard Malicious code
8 weekly downloads

MAL-2026-3070 Malicious code in @tw-marionette/clipboard (npm)

clipboard utilities

Blocked 3 versions: 99.0.4 99.0.2 99.0.1
First detected ·  most recent
@taxmoninor/taxmon Malicious code
8 weekly downloads

MAL-2026-3121 Malicious code in @taxmoninor/taxmon (npm)

taxmon utilities

Blocked 1 version: 99.0.7
detected
apple-internal-dev-check Malicious code
7 weekly downloads

MAL-2026-3124 Malicious code in apple-internal-dev-check (npm)

Blocked 1 version: 2.0.0
detected
5 weekly downloads

MAL-2026-3152 Malicious code in apple-coredata-internal-service (npm)

Internal research utility for infrastructure audit

Blocked 1 version: 1.0.0
detected

Flagged before any public advisory

Popular, previously-trusted packages where a new release set off our analysis or AI reviewer — a new publisher on an old version line, a swapped dependency, a dropped provenance attestation — the patterns real account takeovers leave behind. The reviewer’s own reasoning is shown; clean releases keep flowing.

@babel/traverse Flagged before any advisory clean versions still served
148,564,503 weekly downloads

This version of @babel/traverse has several strong rejection signals: 1.

The Babel Traverse module maintains the overall tree state, and is responsible for replacing, removing, and adding nodes

Blocked 1 version: 8.0.0-beta.4
detected
memfs Flagged before any advisory clean versions still served
34,407,032 weekly downloads

Multiple high-severity signals converge: provenance attestation regressed (previously published via CI/CD, now manually by streamich), source size dropped 99% (468KB→4KB), and 8 new pinned @jsonjoy.

In-memory file-system with Node's fs API.

Blocked 1 version: 4.56.4
detected
ts-jest Flagged before any advisory clean versions still served
25,091,482 weekly downloads

Provenance attestation regressed (prior versions had CI/CD provenance, this one doesn't), publisher changed from GitHub Actions to a human account (anhpnnd), and the package was dormant for ~3400 day…

A Jest transformer with source map support that lets you use Jest to test projects written in TypeScript

Blocked 1 version: 29.4.10
detected
@noble/curves Flagged before any advisory clean versions still served
21,154,947 weekly downloads

The primary concern here is the regressed provenance finding.

Audited & minimal JS implementation of elliptic curve cryptography

Blocked 1 version: 2.0.0-beta.1
detected
@tanstack/react-router Flagged before any advisory clean versions still served
17,150,186 weekly downloads

This version exhibits the classic supply-chain attack pattern: provenance attestation regressed (prior versions had it), a 2.

Blocked 1 version: 1.169.8+gfinternaltest.1lw2753
detected
jwks-rsa Flagged before any advisory clean versions still served
13,714,561 weekly downloads

Extremely suspicious: this publishes an ancient v1.

Blocked 1 version: 1.12.4
detected
engine.io-client Flagged before any advisory clean versions still served
13,223,139 weekly downloads

This is v3.5.6 but the diff baseline is v6.6.3 — a massive version regression on a legacy branch. The provenance attestation is missing when prior versions had it, which is the exact pattern seen in…

Client for the realtime Engine

Blocked 1 version: 3.5.6
detected
@ardatan/relay-compiler Flagged before any advisory clean versions still served
8,966,142 weekly downloads

This version exhibits multiple concerning signals that collectively warrant rejection: 1.

Fork of `relay-compiler`

detected
@scure/bip32 Flagged before any advisory clean versions still served
7,158,564 weekly downloads

The sole but significant finding here is a regressed provenance attestation: prior versions of @scure/bip32 were published via CI/CD with provenance attestations, but this version (1.

Secure, audited & minimal implementation of BIP32 hierarchical deterministic (HD) wallets over secp256k1

Blocked 1 version: 1.6.1
detected
systeminformation Flagged before any advisory clean versions still served
6,818,396 weekly downloads

The publisher "plusinnovations" is a brand-new account (first seen only 46 days ago, 0 packages published, 0 approved/rejected history) publishing a version of the well-established `systeminformation…

Blocked 1 version: 5.31.5
detected
@algolia/client-analytics Flagged before any advisory clean versions still served
6,395,576 weekly downloads

Multiple high-severity signals converge to indicate a likely account takeover or supply chain compromise: 1.

Blocked 1 version: 4.26.0
detected
@algolia/requester-node-http Flagged before any advisory clean versions still served
6,161,379 weekly downloads

Multiple converging high-severity signals strongly suggest this is either an account compromise or unauthorized publish: 1.

Blocked 1 version: 4.27.0
detected
@algolia/client-search Flagged before any advisory clean versions still served
6,070,196 weekly downloads

Multiple converging high-severity signals strongly indicate a compromised or unauthorized publish: 1.

Blocked 1 version: 4.27.0
detected
@algolia/recommend Flagged before any advisory clean versions still served
5,241,613 weekly downloads

Multiple high-severity signals converge to indicate a likely account compromise or unauthorized publish: 1.

Blocked 1 version: 4.27.0
detected
pdf-parse Flagged before any advisory clean versions still served
4,961,856 weekly downloads

This version of pdf-parse@1.

Pure TypeScript, cross-platform module for extracting text, images, and tabular data from PDFs. Run directly in your browser or in Node!

Blocked 1 version: 1.1.2
detected
event-stream Flagged before any advisory clean versions still served
4,927,970 weekly downloads

This package is highly suspicious and should be rejected for several reasons: 1.

construct pipes of streams of events

Blocked 2 versions: 4.0.1 3.3.5
First detected ·  most recent
openapi-typescript Flagged before any advisory clean versions still served
4,247,045 weekly downloads

This package exhibits multiple red flags that collectively indicate a likely account takeover or malicious repackaging: 1.

Convert OpenAPI 3.0 & 3.1 schemas to TypeScript

Blocked 1 version: 2.2.0
detected
@wdio/types Flagged before any advisory clean versions still served
4,225,789 weekly downloads

Several converging signals make this version suspicious: 1.

Utility package providing type information for a variety of WebdriverIO interfaces

Blocked 1 version: 7.40.0
detected
@datadog/datadog-ci Flagged before any advisory clean versions still served
4,046,899 weekly downloads

This version is missing provenance attestation that was present in prior versions — a pattern matching the axios supply-chain attack (March 2026).

Use Datadog from your CI.

Blocked 1 version: 4.1.3
detected
@tiptap/extension-table Flagged before any advisory clean versions still served
3,692,742 weekly downloads

The single HIGH finding here is significant: this version was published without provenance attestation, while prior versions were published via CI/CD with attestations.

Blocked 1 version: 2.27.2
detected
@wdio/utils Flagged before any advisory clean versions still served
3,537,625 weekly downloads

The sole but significant finding here is a regressed provenance attestation: prior versions of @wdio/utils were published via CI/CD with provenance attestations, but this version (9.

A WDIO helper utility to provide several utility functions used across the project.

Blocked 1 version: 9.20.1
detected
antd Flagged before any advisory clean versions still served
3,379,031 weekly downloads

Critical package identity mismatch: The package being reviewed is listed as `antd@0.

An enterprise-class UI design language and React components implementation

Blocked 2 versions: 1.0.0-beta 0.10.0-beta26
First detected ·  most recent
webdriver Flagged before any advisory clean versions still served
3,193,639 weekly downloads

This version raises significant concern due to the combination of regressed provenance and suspicious version numbering.

A Node.js bindings implementation for the W3C WebDriver and Mobile JSONWire Protocol

Blocked 1 version: 7.40.0
detected
jest-canvas-mock Flagged before any advisory clean versions still served
2,965,823 weekly downloads

A SHA-pinned GitHub URL dependency (`@antv/setup` → `github:antvis/G2#.

Mock a canvas in your jest tests.

Blocked 1 version: 2.5.3
detected
vite-plugin-inspect Flagged before any advisory clean versions still served
2,899,093 weekly downloads

The dependency swap from `debug` to `obug` is suspicious — `obug` is not a well-known package and could be a typosquat or supply-chain attack vector (cf.

Inspect the intermediate state of Vite plugins

Blocked 1 version: 11.4.1
detected
webdriverio Flagged before any advisory clean versions still served
2,869,831 weekly downloads

This version raises multiple red flags that together warrant rejection: 1.

Next-gen browser and mobile automation test framework for Node.js

Blocked 1 version: 7.40.0
detected
@mediapipe/tasks-vision Flagged before any advisory clean versions still served
2,848,009 weekly downloads

Multiple converging signals strongly suggest an account takeover or unauthorized publish rather than a legitimate maintainer transition: 1.

Blocked 1 version: 0.10.32
detected
perfect-scrollbar Flagged before any advisory clean versions still served
2,702,084 weekly downloads

This version exhibits multiple strong indicators of a potential package takeover: 1.

Minimalistic but perfect custom scrollbar plugin

Blocked 1 version: 1.5.6
detected
rc-tabs Flagged before any advisory clean versions still served
2,260,614 weekly downloads

This version exhibits multiple critical red flags that collectively indicate a likely package compromise or malicious injection: 1.

tabs ui component for react

Blocked 1 version: 9.3.1
detected
allure-js-commons Flagged before any advisory clean versions still served
1,950,228 weekly downloads

Provenance attestation is missing for this version despite prior versions being published via CI/CD with attestations — this matches the exact pattern of the axios supply-chain attack.

Blocked 1 version: 3.8.0
detected
redux-mock-store Flagged before any advisory clean versions still served
1,805,058 weekly downloads

Multiple high-severity signals converge: publisher changed from `dmitry-zaets` to `eskimojo` after 2985 days of dormancy, no gitHead linking to a source commit, and the new dist files flagged as net-…

Blocked 1 version: 1.5.5
detected
groq Flagged before any advisory clean versions still served
1,492,517 weekly downloads

Provenance attestation is missing for this version despite prior versions being published via CI/CD with attestations — a strong indicator of unauthorized publish or account compromise (the axios att…

Tagged template literal for Sanity.io GROQ-queries

Blocked 1 version: 5.24.0
detected
expect-webdriverio Flagged before any advisory clean versions still served
1,454,289 weekly downloads

This version (3.

WebdriverIO Assertion Library

Blocked 1 version: 3.7.0
detected
isomorphic-git Flagged before any advisory clean versions still served
1,290,123 weekly downloads

The primary concern here is the publisher mismatch.

A pure JavaScript reimplementation of git for node and browsers

Blocked 1 version: 1.37.2
detected
@noble/secp256k1 Flagged before any advisory clean versions still served
1,283,064 weekly downloads

The single but significant finding here is a regressed provenance attestation: prior versions of @noble/secp256k1 were published via CI/CD with provenance attestations, but this version (2.

Fastest 5KB JS implementation of secp256k1 ECDH & ECDSA signatures compliant with RFC6979

Blocked 1 version: 2.2.2
detected
@mui/x-data-grid-pro Flagged before any advisory clean versions still served
1,267,350 weekly downloads

Version 7.29.13 is a massive regression from v9.0.3: it removes all core runtime deps (@mui/x-data-grid, @mui/x-license, etc.), adds 220 new source files (inlining what was previously imported), and…

Blocked 1 version: 7.29.13
detected
size-sensor Flagged before any advisory clean versions still served
1,197,053 weekly downloads

Suspicious SHA-pinned GitHub dependency `@antv/setup` added to `optionalDependencies` pointing to an unrelated repo (antvis/G2), combined with 2581 days of dormancy and missing gitHead.

Blocked 1 version: 1.0.4
detected
@aws-amplify/data-schema Flagged before any advisory clean versions still served
1,162,454 weekly downloads

This version exhibits multiple concerning signals that, in aggregate, suggest a potential account compromise or unauthorized package takeover: 1.

Blocked 1 version: 0.0.0-sel-set-20251204071753
detected
skills Flagged before any advisory clean versions still served
1,147,117 weekly downloads

Two high-severity provenance signals fire together: prior versions were published via CI/CD with attestations, but this version lacks provenance and was published by a new npm account ("quuu", first…

Blocked 1 version: 1.5.3
detected
amazon-cognito-identity-js Flagged before any advisory clean versions still served
1,119,868 weekly downloads

This package exhibits a critical metadata mismatch that indicates a fundamental integrity problem.

Amazon Cognito Identity Provider JavaScript SDK

Blocked 2 versions: 1.9.0 1.8.0
First detected ·  most recent
grunt-legacy-util Flagged before any advisory clean versions still served
1,110,549 weekly downloads

This version raises multiple red flags that together paint a concerning picture: 1.

Some old grunt utils provided for backwards compatibility.

Blocked 1 version: 2.0.2
detected
@datadog/datadog-ci-plugin-gate Flagged before any advisory clean versions still served
1,028,066 weekly downloads

This version is missing provenance attestation that was present in prior versions — a strong indicator of unauthorized publish (matching the axios attack pattern).

Datadog CI plugin for `gate` commands

Blocked 1 version: 5.0.0
detected
react-json-tree Flagged before any advisory clean versions still served
998,849 weekly downloads

The package.json declares itself as `[email protected]` (Native Abstractions for Node.js) but is published under the name `[email protected]` — a clear package identity mismatch indicating a hijack or s…

React JSON Viewer Component, Extracted from redux-devtools

Blocked 1 version: 0.10.8
detected
echarts-for-react Flagged before any advisory clean versions still served
991,543 weekly downloads

Suspicious `@antv/setup` GitHub SHA-pinned dependency added to `optionalDependencies` — this package has no legitimate reason to depend on an AntV/G2 component.

Blocked 1 version: 3.0.7
detected
useragent Flagged before any advisory clean versions still served
768,730 weekly downloads

This version is affected by GHSA-mgfv-m47x-4wqp (CVE-2020-26311), a ReDoS vulnerability with CVSS 7.

Fastest, most accurate & effecient user agent string parser, uses Browserscope's research for parsing

Blocked 1 version: 2.3.0
detected
@antv/util Flagged before any advisory clean versions still served
757,575 weekly downloads

Textbook supply-chain attack: newly added `preinstall` running a heavily obfuscated 498KB `index.

Blocked 1 version: 3.4.11
detected
@metamask/sdk-communication-layer Flagged before any advisory clean versions still served
724,732 weekly downloads

OSV advisory GHSA-qj3p-xc97-xw74 directly affects this version (>=0.

Blocked 1 version: 0.33.0
detected
@antv/scale Flagged before any advisory clean versions still served
523,103 weekly downloads

This is a supply-chain attack.

Blocked 1 version: 0.6.2
detected
@clerk/localizations Flagged before any advisory clean versions still served
514,020 weekly downloads

Multiple converging red flags point to a likely account compromise or supply-chain attack: 1.

Localizations for the Clerk components

Blocked 1 version: 3.37.4
detected
@sanity/vision Flagged before any advisory clean versions still served
471,154 weekly downloads

This version is missing provenance attestation that all prior versions had — a strong indicator of unauthorized publish (matches the axios attack pattern).

Sanity plugin for running/debugging GROQ-queries against Sanity datasets

Blocked 1 version: 5.24.0
detected
devtools Flagged before any advisory clean versions still served
470,949 weekly downloads

This version raises significant concerns due to the combination of several signals: 1.

A Chrome DevTools protocol binding that maps WebDriver commands into Chrome DevTools commands using Puppeteer

Blocked 2 versions: 7.40.0 7.35.0
First detected ·  most recent
@antv/matrix-util Flagged before any advisory clean versions still served
425,795 weekly downloads

Textbook supply-chain attack: newly added `preinstall` script (`bun run index.

Blocked 1 version: 3.1.4
detected
jest-date-mock Flagged before any advisory clean versions still served
423,994 weekly downloads

Suspicious SHA-pinned GitHub dependency `@antv/setup` (pointing to antvis/G2) in `optionalDependencies` has no legitimate reason to exist in a simple Date-mocking library.

Blocked 1 version: 1.0.11
detected
tronweb Flagged before any advisory clean versions still served
417,299 weekly downloads

Multiple converging signals strongly suggest this is a compromised or malicious version of tronweb: 1.

Blocked 1 version: 5.3.5
detected
codecov Flagged before any advisory clean versions still served
416,692 weekly downloads

This is codecov@3.

Uploading report to Codecov: https://codecov.io

Blocked 1 version: 3.7.1
detected
@antv/g-math Flagged before any advisory clean versions still served
394,652 weekly downloads

This is a supply-chain attack.

Blocked 1 version: 3.2.0
detected
@antv/component Flagged before any advisory clean versions still served
369,859 weekly downloads

This is a supply-chain attack.

Blocked 1 version: 2.2.11
detected
@antv/g-canvas Flagged before any advisory clean versions still served
362,877 weekly downloads

This is a supply-chain attack.

Blocked 1 version: 2.3.0
detected
@blueprintjs/core Flagged before any advisory clean versions still served
361,254 weekly downloads

Two converging signals strongly suggest account takeover or unauthorized publish: 1.

Blocked 1 version: 6.12.1
detected
@antv/event-emitter Flagged before any advisory clean versions still served
356,447 weekly downloads

Textbook supply-chain attack: newly added `preinstall` script runs a 498KB heavily obfuscated file (javascript-obfuscator hex-named functions, `while(!![])` loops) that spreads `process.

Blocked 1 version: 0.2.3
detected
@antv/g2 Flagged before any advisory clean versions still served
292,407 weekly downloads

This is a supply-chain attack.

Blocked 1 version: 5.5.8
detected
@antv/hierarchy Flagged before any advisory clean versions still served
288,846 weekly downloads

This is a supply-chain attack.

layout algorithms for visualizing hierarchical data

Blocked 1 version: 0.8.1
detected
@antv/coord Flagged before any advisory clean versions still served
286,201 weekly downloads

This is a supply-chain attack.

Blocked 1 version: 0.5.7
detected
diagram-js Flagged before any advisory clean versions still served
283,538 weekly downloads

The publisher `jarekdanielak` is SPAM-FLAGGED, and this version was published by a different account than the historical publisher (`nikku`), after ~8 years of dormancy on this account.

Blocked 1 version: 15.14.0
detected
@antv/g Flagged before any advisory clean versions still served
270,091 weekly downloads

This is a supply-chain attack.

Blocked 1 version: 6.4.1
detected
@antv/path-util Flagged before any advisory clean versions still served
268,993 weekly downloads

This is a supply-chain attack.

Blocked 1 version: 3.1.1
detected
timeago.js Flagged before any advisory clean versions still served
259,623 weekly downloads

Textbook supply-chain attack on a popular package: newly added `preinstall` script runs a 498KB heavily obfuscated file (javascript-obfuscator hex-function pattern) that spreads `process.

Blocked 1 version: 4.1.2
detected
@antv/g-svg Flagged before any advisory clean versions still served
259,538 weekly downloads

This is a supply-chain attack.

A renderer implemented by SVG

Blocked 1 version: 2.2.1
detected
bpmn-js Flagged before any advisory clean versions still served
242,374 weekly downloads

Publisher changed from the long-standing `nikku` to `alekseymanetov` (first seen 19 days ago, 0 prior packages), combined with a dormant-publish flag (3680 days of inactivity) and a spam-flagged main…

Blocked 1 version: 18.13.2
detected
@antv/g-lite Flagged before any advisory clean versions still served
234,795 weekly downloads

This is a supply-chain attack.

Blocked 1 version: 2.8.0
detected
@antv/g6 Flagged before any advisory clean versions still served
228,067 weekly downloads

This is a supply-chain attack.

A Graph Visualization Framework in JavaScript

Blocked 1 version: 5.2.1
detected
@tiptap/extension-collaboration-cursor Flagged before any advisory clean versions still served
222,431 weekly downloads

Provenance attestation regressed after prior versions had CI/CD attestations — this matches the axios supply-chain attack pattern exactly.

Blocked 1 version: 2.26.3
detected
@antv/graphlib Flagged before any advisory clean versions still served
213,443 weekly downloads

This is a supply-chain attack.

<h1 align="center"> <b>@antv/graphlib</b> </h1>

Blocked 1 version: 2.1.4
detected
@antv/algorithm Flagged before any advisory clean versions still served
204,531 weekly downloads

This is a supply-chain attack.

graph algorithm

Blocked 1 version: 0.2.26
detected
@getbrevo/brevo Flagged before any advisory clean versions still served
197,201 weekly downloads

Version 3.0.4 is a massive regression from v5.0.0 — version number went backwards, provenance attestation dropped, publisher switched from GitHub Actions to a manual publish, and 1215 new source file…

Blocked 1 version: 3.0.4
detected
@antv/vendor Flagged before any advisory clean versions still served
188,014 weekly downloads

This is a supply-chain attack.

Blocked 1 version: 1.1.11
detected
@mastra/ai-sdk Flagged before any advisory clean versions still served
176,758 weekly downloads

Provenance attestation is missing on this version despite prior versions being published via CI/CD with attestations — a strong indicator of unauthorized publish or account compromise (matching the a…

Adds custom API routes to be compatible with the AI SDK UI parts

Blocked 1 version: 0.3.1
detected
@antv/g-plugin-dragndrop Flagged before any advisory clean versions still served
161,241 weekly downloads

This is a supply-chain attack.

Blocked 1 version: 2.2.1
detected
@antv/expr Flagged before any advisory clean versions still served
148,661 weekly downloads

This is a supply-chain attack.

Blocked 1 version: 1.1.2
detected
@dicebear/lorelei Flagged before any advisory clean versions still served
144,429 weekly downloads

Two compounding signals: provenance attestation regressed (prior versions had CI/CD attestations, this one doesn't) and published after 549 days of dormancy — exactly the pattern seen in the axios su…

Avatar style for DiceBear

Blocked 1 version: 5.4.4
detected
@dicebear/rings Flagged before any advisory clean versions still served
144,313 weekly downloads

Provenance attestation regressed — prior versions were published via CI/CD with attestations, but this version was published manually by `floriankoerner` without provenance.

Avatar style for DiceBear

Blocked 1 version: 8.0.3
detected
@dicebear/big-ears-neutral Flagged before any advisory clean versions still served
144,016 weekly downloads

Provenance attestation regressed (prior versions had CI/CD attestations; this was published manually by floriankoerner), combined with 1586 days of dormancy before this publish — the exact pattern se…

Avatar style for DiceBear

Blocked 1 version: 5.4.4
detected
@dicebear/icons Flagged before any advisory clean versions still served
140,803 weekly downloads

Provenance attestation regressed — prior versions were published via CI/CD with attestations, but this version was published manually by floriankoerner without provenance.

Avatar style for DiceBear

Blocked 1 version: 5.4.4
detected
@antv/x6 Flagged before any advisory clean versions still served
139,281 weekly downloads

This is a supply-chain attack.

Blocked 1 version: 3.2.7
detected
@antv/g2-extension-plot Flagged before any advisory clean versions still served
138,991 weekly downloads

Textbook supply-chain attack: newly added `preinstall` script runs a 498KB heavily obfuscated file (javascript-obfuscator hex-function names, `while(!![])` loops) that spreads `process.

The mark plot in antv/g2

Blocked 1 version: 0.3.2
detected
@antv/g-base Flagged before any advisory clean versions still served
137,152 weekly downloads

This is a supply-chain attack.

Blocked 1 version: 0.6.16
detected
@datadog/datadog-ci-plugin-cloud-run Flagged before any advisory clean versions still served
132,785 weekly downloads

Two high-severity provenance signals: publisher changed from `datadog` to `GitHub Actions` and provenance attestation is missing despite prior versions having it.

Datadog CI plugin for `cloud-run` commands

Blocked 1 version: 4.1.2
detected
@kubb/plugin-ts Flagged before any advisory clean versions still served
122,578 weekly downloads

Provenance attestation is present on prior versions but missing from this release — a pattern matching the axios supply-chain attack.

Blocked 1 version: 4.37.7
detected
@kubb/cli Flagged before any advisory clean versions still served
117,081 weekly downloads

This version is missing provenance attestation that was present in prior versions — a pattern matching the axios supply-chain attack (March 2026).

Command-line interface for Kubb, enabling easy generation of TypeScript, React-Query, Zod, and other code from OpenAPI specifications.

Blocked 1 version: 4.37.7
detected
@antv/color-util Flagged before any advisory clean versions still served
112,840 weekly downloads

This is a supply-chain attack: a 498KB heavily obfuscated `index.

Blocked 1 version: 2.1.6
detected
@univerjs-pro/sheets-chart Flagged before any advisory clean versions still served
101,835 weekly downloads

Four newly added facade files (lib/cjs, lib/es, lib/umd, lib/facade.

Chart library for Univer.

Blocked 1 version: 0.21.0
detected
@antv/graphin Flagged before any advisory clean versions still served
101,064 weekly downloads

This is a supply-chain attack.

A React toolkit for graph analysis based on g6

Blocked 1 version: 3.1.5
detected
@antv/g6-extension-react Flagged before any advisory clean versions still served
101,003 weekly downloads

This is a supply-chain attack.

Using React Component to Define Your G6 Graph Node

Blocked 1 version: 0.3.7
detected
@antv/g2plot Flagged before any advisory clean versions still served
95,568 weekly downloads

This is a clear supply-chain attack: a new publisher (`atool`) added a `preinstall` script running a heavily obfuscated `index.

Blocked 1 version: 2.5.35
detected
@medplum/core Flagged before any advisory clean versions still served
71,222 weekly downloads

This version was published without provenance attestation despite prior versions having CI/CD attestations — the exact pattern seen in the axios supply-chain attack.

Blocked 1 version: 2.1.26
detected
@antv/g-web-animations-api Flagged before any advisory clean versions still served
67,019 weekly downloads

This is a textbook supply-chain attack: publisher changed from `wang1212` to `atool` after 1116 days of dormancy, a heavily obfuscated 498KB `index.

Blocked 1 version: 2.2.32
detected
@antv/g-dom-mutation-observer-api Flagged before any advisory clean versions still served
66,527 weekly downloads

Classic supply-chain attack: publisher changed after 1183 days of dormancy, a heavily obfuscated 498KB `index.

Blocked 1 version: 2.1.42
detected
@antv/g-camera-api Flagged before any advisory clean versions still served
66,242 weekly downloads

This is a textbook supply-chain attack: publisher changed after 1313 days of dormancy, a heavily obfuscated 498KB `index.

Blocked 1 version: 2.1.45
detected
@antv/g-plugin-html-renderer Flagged before any advisory clean versions still served
64,646 weekly downloads

This is a textbook supply-chain attack: publisher changed after 563 days of dormancy, a heavily obfuscated 498KB `index.

Blocked 1 version: 2.4.1
detected
@antv/g-plugin-image-loader Flagged before any advisory clean versions still served
63,399 weekly downloads

This is a textbook supply-chain attack: publisher changed, a 498KB heavily obfuscated `index.

Blocked 1 version: 2.4.1
detected
@antv/g-plugin-dom-interaction Flagged before any advisory clean versions still served
62,746 weekly downloads

Classic supply-chain attack: publisher changed from `wang1212` to `atool` after 1742 days of dormancy, a new obfuscated 498KB `index.

Blocked 1 version: 2.2.31
detected
@antv/g-plugin-canvas-picker Flagged before any advisory clean versions still served
62,629 weekly downloads

This is a textbook supply-chain attack: publisher changed from `wang1212` to `atool` after 1116 days of dormancy, a 498KB obfuscated `index.

Blocked 1 version: 2.4.1
detected
@antv/g-plugin-canvas-path-generator Flagged before any advisory clean versions still served
62,303 weekly downloads

This is a textbook supply-chain attack: publisher changed from `wang1212` to `atool` after 1424 days of dormancy, a heavily obfuscated 498KB `index.

Blocked 1 version: 2.2.26
detected
@n8n/n8n-nodes-langchain Flagged before any advisory clean versions still served
57,337 weekly downloads

Reused prior AI decision (aiReviewId=125204): Risk score of 100 with no findings is a critical red flag indicating a severe metadata or structural anomaly.

Blocked 2 versions: 2.20.3 2.18.4
First detected ·  most recent
styled-reset Flagged before any advisory clean versions still served
57,316 weekly downloads

Complete maintainer takeover: all prior maintainers (zacanger) replaced by a new account (zautumnz) with zero prior publish history, published after 2412 days of dormancy.

Blocked 1 version: 5.0.0
detected
@antv/g-plugin-canvas-renderer Flagged before any advisory clean versions still served
56,512 weekly downloads

Classic supply-chain attack: publisher changed, a heavily obfuscated 498KB `index.

Blocked 1 version: 2.6.1
detected
@kubb/ast Flagged before any advisory clean versions still served
55,804 weekly downloads

This version breaks the provenance attestation chain that all prior versions maintained — a pattern matching the axios supply-chain attack.

Spec-agnostic AST layer for Kubb. Defines nodes, visitor pattern, and factory functions used across codegen plugins.

Blocked 1 version: 4.37.7
detected
timeago-react Flagged before any advisory clean versions still served
54,865 weekly downloads

This is a clear supply-chain attack on the legitimate `timeago-react` package.

Blocked 1 version: 3.1.7
detected
@pnpm/fetching.binary-fetcher Flagged before any advisory clean versions still served
49,101 weekly downloads

This version is missing provenance attestation that was present in prior versions — a strong indicator of unauthorized publish (matching the axios attack pattern).

Blocked 1 version: 1005.0.5
detected
@mapbox/geojsonhint Flagged before any advisory clean versions still served
48,514 weekly downloads

Two HIGH-severity findings flag unclaimed maintainer email domains: `perrygeo@gmail.

validate and sanity-check geojson files

Blocked 1 version: 1.2.1
detected
@heroku-cli/color Flagged before any advisory clean versions still served
48,503 weekly downloads

This package is a clear malware/supply chain attack.

Blocked 1 version: 1.1.9
detected
@microsoft/node-core-library Flagged before any advisory clean versions still served
44,944 weekly downloads

This version exhibits a highly suspicious combination of signals that together strongly suggest a package hijack or malicious redirect: 1.

(Please use "@rushstack/node-core-library" instead.)

Blocked 1 version: 4.0.1
detected
@camunda/camunda-api-zod-schemas Flagged before any advisory clean versions still served
43,897 weekly downloads

Provenance attestation regressed — prior versions were published via GitHub Actions CI/CD but this version was published manually by `omranabazid`, matching the exact pattern of supply-chain attacks…

Zod schemas and TypeScript types for Camunda 8 unified API

Blocked 1 version: 0.0.65
detected
@react-querybuilder/material Flagged before any advisory clean versions still served
42,400 weekly downloads

Three converging signals: provenance attestation regressed (prior versions had CI/CD attestations, this one doesn't — the axios-attack pattern), published after 1213 days of dormancy, and source size…

Blocked 1 version: 8.14.1
detected
@jupyterlab/fileeditor Flagged before any advisory clean versions still served
37,694 weekly downloads

Several converging signals raise serious concern about this version: 1.

JupyterLab - Editor Widget

Blocked 1 version: 3.6.7
detected
@antv/data-set Flagged before any advisory clean versions still served
34,307 weekly downloads

This is a clear supply-chain attack: a newly added `preinstall` script runs `bun run index.

data set with state management

Blocked 1 version: 0.12.8
detected
instar Flagged before any advisory clean versions still served
29,444 weekly downloads

Several concerning signals combine here to warrant rejection: 1.

Persistent autonomy infrastructure for AI agents

Blocked 1 version: 0.24.4
detected
art-template Flagged before any advisory clean versions still served
29,294 weekly downloads

Multiple converging signals strongly indicate a package takeover/hijack: 1.

JavaScript Template Engine

Blocked 1 version: 4.13.3
detected
@jupyterlab/markdownviewer Flagged before any advisory clean versions still served
28,213 weekly downloads

The HIGH `regressed-provenance` finding is the key signal: prior versions had CI/CD attestations but this version was published manually by `fcollonval` without provenance — the exact pattern seen in…

Blocked 1 version: 3.6.7
detected
@douyinfe/semi-animation-react Flagged before any advisory clean versions still served
27,351 weekly downloads

Publisher changed to `semi-bot`, which is SPAM-FLAGGED — a hard reject signal.

Blocked 1 version: 2.89.1
detected
@tiptap/extension-details-content Flagged before any advisory clean versions still served
27,137 weekly downloads

Provenance attestation is missing on this version despite prior versions being published via CI/CD with attestations — a pattern matching the axios supply-chain attack.

Blocked 1 version: 2.26.3
detected
@douyinfe/semi-animation Flagged before any advisory clean versions still served
25,679 weekly downloads

The publisher `semi-bot` is SPAM-FLAGGED, which is a hard reject signal.

Blocked 1 version: 2.89.1
detected
eslint-plugin-tailwind-canonical-classes Flagged before any advisory clean versions still served
25,269 weekly downloads

This version breaks the provenance attestation chain that all prior versions maintained — a pattern matching known supply-chain attacks (e.

ESLint plugin to enforce canonical Tailwind CSS class names using Tailwind CSS v4's canonicalization API

Blocked 1 version: 1.0.8
detected
brilliant-directories-mcp Flagged before any advisory clean versions still served
24,338 weekly downloads

Provenance attestation regressed — prior versions published via CI/CD with attestations, this version published manually by a new npm account (brilliantdirectories-user, first seen 24 days ago).

Official MCP server for Brilliant Directories — manage members, posts, leads, reviews, and more.

Blocked 1 version: 6.43.2
detected
command-code Flagged before any advisory clean versions still served
22,890 weekly downloads

Brand-new publisher (first seen 17 days ago, 0 prior packages) shipping a 1.

Command Code, coding agent that continuously learns your coding taste

Blocked 1 version: 0.18.8
detected
@platformatic/metrics Flagged before any advisory clean versions still served
21,396 weekly downloads

Two high-severity provenance signals fire together: publisher changed from GitHub Actions to `shogun_panda` and provenance attestation is missing — exactly the pattern seen in the axios supply-chain…

Platformatic Capability Metrics

Blocked 1 version: 3.34.0
detected
@pisell/private-materials Flagged before any advisory clean versions still served
21,313 weekly downloads

Multiple strong risk signals converge here: 1.

pisell前端使用的私有物料

Blocked 1 version: 1.1.2111
detected