← All packages

Supply-chain attacks we’ve detected

Popular npm packages whose release stream was tampered with — either a version OSV confirmed as malicious code, or a version our own analysis flagged as a likely account takeover before any public advisory. None of these versions were ever served from this registry; where the package still has clean releases, those keep flowing.

200
Packages hit
300
Blocked versions
73
Confirmed malware (OSV)
127
Detected before any advisory

Show all · updated

Confirmed malicious releases

Versions OSV’s malicious-packages dataset confirms contained malicious code. We blocked these the moment the advisory landed — or before, then OSV agreed.

fsevents Malicious code clean versions still served
32,732,849 weekly downloads

MAL-2023-462 Malicious code in fsevents (npm)

Native Access to MacOS FSEvents

First detected ·  most recent
fs Malicious code clean versions still served
1,848,666 weekly downloads

MAL-2025-21003 Malicious code in fs (npm)

This package name is not currently in use, but was formerly occupied by another package. To avoid malicious use, npm is hanging on to the package name, but loosely, and we'll probably give it to you if you want it.

Blocked 2 versions: 0.0.2 0.0.0
First detected ·  most recent
@bitwarden/cli Malicious code clean versions still served
95,180 weekly downloads

MAL-2026-3020 Malicious code in @bitwarden/cli (npm)

A secure and free password manager for all of your devices.

Blocked 1 version: 2026.4.0
detected
@antv/l7 Malicious code clean versions still served
45,765 weekly downloads

MAL-2026-4033 Malicious code in @antv/l7 (npm)

Blocked 2 versions: 2.27.10 2.26.10
First detected ·  most recent
@antv/l7-maps Malicious code clean versions still served
44,717 weekly downloads

MAL-2026-4045 Malicious code in @antv/l7-maps (npm)

Blocked 2 versions: 2.27.10 2.26.10
First detected ·  most recent
@pisell/pisellos Malicious code clean versions still served
5,030 weekly downloads

MAL-2026-4417 Malicious code in @pisell/pisellos (npm)

一个可扩展的前端模块化SDK框架,支持插件系统

Blocked 1 version: 2.2.172
detected
@ensdomains/ens-contracts Malicious code
4,205 weekly downloads

MAL-2025-190931 Malicious code in @ensdomains/ens-contracts (npm)

Blocked 1 version: 1.7.0
detected
@onerjs/addons Malicious code clean versions still served
1,481 weekly downloads

MAL-2026-4410 Malicious code in @onerjs/addons (npm)

Blocked 1 version: 8.52.3
detected
764 weekly downloads

MAL-2026-2055 Malicious code in @emilgroup/partner-sdk-node (npm)

OpenAPI client for @emilgroup/partner-sdk-node

First detected ·  most recent
frank-bot-gogle-cloning Malicious code
480 weekly downloads

MAL-2026-3080 Malicious code in frank-bot-gogle-cloning (npm)

Security audit module

Blocked 1 version: 1.1.0
detected
@antv/gpt-vis-ssr Malicious code clean versions still served
458 weekly downloads

MAL-2026-4021 Malicious code in @antv/gpt-vis-ssr (npm)

SSR(Server Side Render) for AntV GPT-Vis.

Blocked 1 version: 0.5.7
detected
@emilgroup/task-sdk-node Malicious code clean versions still served
415 weekly downloads

MAL-2026-2079 Malicious code in @emilgroup/task-sdk-node (npm)

OpenAPI client for @emilgroup/task-sdk-node

Blocked 2 versions: 1.0.3 1.0.2
First detected ·  most recent
@emilgroup/task-sdk Malicious code clean versions still served
296 weekly downloads

MAL-2026-2078 Malicious code in @emilgroup/task-sdk (npm)

OpenAPI client for @emilgroup/task-sdk

Blocked 1 version: 1.0.2
detected
@clearpool/table Malicious code
258 weekly downloads

MAL-2026-3058 Malicious code in @clearpool/table (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 9.9.9
First detected ·  most recent
@clearpool/streaming Malicious code
255 weekly downloads

MAL-2026-3057 Malicious code in @clearpool/streaming (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 9.9.9
First detected ·  most recent
@clearpool/utils Malicious code
251 weekly downloads

MAL-2026-3059 Malicious code in @clearpool/utils (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 9.9.9
First detected ·  most recent
@clearpool/comms Malicious code
213 weekly downloads

MAL-2026-3056 Malicious code in @clearpool/comms (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 9.9.9
First detected ·  most recent
frank-research-poc-apple Malicious code
213 weekly downloads

MAL-2026-3081 Malicious code in frank-research-poc-apple (npm)

Blocked 1 version: 1.1.4
detected
uipath-ui-widgets Malicious code
213 weekly downloads

MAL-2026-3036 Malicious code in uipath-ui-widgets (npm)

Blocked 1 version: 1.0.1
detected
rtms-manager Malicious code
207 weekly downloads

MAL-2026-2862 Malicious code in rtms-manager (npm)

Dependency Confusion poc

Blocked 2 versions: 1.4.0 1.2.0
First detected ·  most recent
standalone-apps Malicious code
205 weekly downloads

MAL-2026-3037 Malicious code in standalone-apps (npm)

Blocked 1 version: 1.0.1
detected
react-dnd-14 Malicious code
194 weekly downloads

MAL-2026-3196 Malicious code in react-dnd-14 (npm)

Blocked 1 version: 99.9.1
detected
wm-plugin-teach-me-widget Malicious code
181 weekly downloads

MAL-2026-3128 Malicious code in wm-plugin-teach-me-widget (npm)

Security testing test package

Blocked 1 version: 21.0.31
detected
apollo-landing Malicious code
156 weekly downloads

MAL-2026-3038 Malicious code in apollo-landing (npm)

Blocked 1 version: 1.0.1
detected
apollo-vertex Malicious code
154 weekly downloads

MAL-2026-3040 Malicious code in apollo-vertex (npm)

Blocked 1 version: 1.0.1
detected
process-app-task Malicious code
152 weekly downloads

MAL-2026-3039 Malicious code in process-app-task (npm)

Blocked 1 version: 1.0.1
detected
axis-abc-search-address Malicious code
148 weekly downloads

MAL-2026-3076 Malicious code in axis-abc-search-address (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
axis-abc-portal-menu Malicious code
148 weekly downloads

MAL-2026-3074 Malicious code in axis-abc-portal-menu (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
apcyber-test-package Malicious code
143 weekly downloads

MAL-2026-3304 Malicious code in apcyber-test-package (npm)

Internal automation library.

Blocked 2 versions: 100.0.0 99.99.99
First detected ·  most recent
axis-abc-search-account Malicious code
139 weekly downloads

MAL-2026-3075 Malicious code in axis-abc-search-account (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
path-internal-util Malicious code
137 weekly downloads

MAL-2026-3312 Malicious code in path-internal-util (npm)

Node.js path module

Blocked 1 version: 1.0.1
detected
@activation_code/activate Malicious code
72 weekly downloads

MAL-2026-3106 Malicious code in @activation_code/activate (npm)

activate utilities

Blocked 1 version: 99.0.3
detected
tether-base Malicious code
64 weekly downloads

MAL-2026-3033 Malicious code in tether-base (npm)

Test package for dependency confusion detection

Blocked 1 version: 99.0.0
detected
@alfa.life.mapp/app.web Malicious code
37 weekly downloads

MAL-2026-3052 Malicious code in @alfa.life.mapp/app.web (npm)

app.web utilities

Blocked 3 versions: 99.0.18 99.0.16 99.0.15
First detected ·  most recent
30 weekly downloads

MAL-2026-3053 Malicious code in @apple-pay-trust/merchant-session (npm)

merchant-session utilities

Blocked 2 versions: 99.0.3 99.0.1
First detected ·  most recent
28 weekly downloads

MAL-2026-3111 Malicious code in @apple-pay-trust/authorize-payment (npm)

authorize-payment utilities

Blocked 1 version: 99.0.3
detected
@apiary-annex/title Malicious code
28 weekly downloads

MAL-2026-3110 Malicious code in @apiary-annex/title (npm)

title utilities

Blocked 1 version: 99.0.3
detected
@apiary-annex/meta Malicious code
28 weekly downloads

MAL-2026-3109 Malicious code in @apiary-annex/meta (npm)

meta utilities

Blocked 1 version: 99.0.3
detected
27 weekly downloads

MAL-2026-3112 Malicious code in @apple-pay-trust/cancelled (npm)

cancelled utilities

Blocked 2 versions: 99.0.4 99.0.3
First detected ·  most recent
26 weekly downloads

MAL-2026-3113 Malicious code in @apple-pay-trust/check-apple-pay-result (npm)

check-apple-pay-result utilities

Blocked 1 version: 99.0.3
detected
@apple-pay-trust/start Malicious code
25 weekly downloads

MAL-2026-3054 Malicious code in @apple-pay-trust/start (npm)

start utilities

Blocked 3 versions: 99.0.4 99.0.3 99.0.1
First detected ·  most recent
23 weekly downloads

MAL-2026-3116 Malicious code in @business_promocode/apply_promocode (npm)

apply_promocode utilities

Blocked 1 version: 99.0.3
detected
22 weekly downloads

MAL-2026-3115 Malicious code in @b2b_blocker/show_activation_error (npm)

show_activation_error utilities

Blocked 2 versions: 99.0.4 99.0.3
First detected ·  most recent
20 weekly downloads

MAL-2026-3117 Malicious code in @business_promocode/cancel_promocode (npm)

cancel_promocode utilities

Blocked 1 version: 99.0.3
detected
@ozon-complt/split Malicious code
19 weekly downloads

MAL-2026-3067 Malicious code in @ozon-complt/split (npm)

split utilities

Blocked 2 versions: 99.0.4 99.0.2
First detected ·  most recent
@voiceflow/google-types Malicious code
19 weekly downloads

MAL-2025-191352 Malicious code in @voiceflow/google-types (npm)

Google service types

Blocked 1 version: 2.21.14
detected
18 weekly downloads

MAL-2026-3061 Malicious code in @google-pay-trust/authorize-payment (npm)

authorize-payment utilities

Blocked 3 versions: 99.0.4 99.0.3 99.0.1
First detected ·  most recent
axis-charts Malicious code
18 weekly downloads

MAL-2026-3077 Malicious code in axis-charts (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
17 weekly downloads

MAL-2026-3066 Malicious code in @ozon-complt/antibot-handler (npm)

antibot-handler utilities

Blocked 3 versions: 99.0.4 99.0.2 99.0.1
First detected ·  most recent
17 weekly downloads

MAL-2026-3064 Malicious code in @google-pay-trust/init-google-pay (npm)

init-google-pay utilities

Blocked 2 versions: 99.0.2 99.0.1
First detected ·  most recent
axis-notification Malicious code
17 weekly downloads

MAL-2026-3078 Malicious code in axis-notification (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
axis-ui-generator Malicious code
17 weekly downloads

MAL-2026-3079 Malicious code in axis-ui-generator (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
17 weekly downloads

MAL-2026-3062 Malicious code in @google-pay-trust/cancelled (npm)

cancelled utilities

Blocked 1 version: 99.0.1
detected
@apple-pay-trust/finish Malicious code
16 weekly downloads

MAL-2026-3114 Malicious code in @apple-pay-trust/finish (npm)

finish utilities

Blocked 2 versions: 99.0.4 99.0.3
First detected ·  most recent
16 weekly downloads

MAL-2026-3055 Malicious code in @apple-pay-trust/validate-merchant (npm)

validate-merchant utilities

Blocked 3 versions: 99.0.4 99.0.3 99.0.1
First detected ·  most recent
@w3m-frame/session_update Malicious code
16 weekly downloads

MAL-2026-3122 Malicious code in @w3m-frame/session_update (npm)

session_update utilities

Blocked 1 version: 99.0.4
detected
@tw-utils/static Malicious code
15 weekly downloads

MAL-2026-3073 Malicious code in @tw-utils/static (npm)

static utilities

Blocked 4 versions: 99.0.4 99.0.3 99.0.2 99.0.1
First detected ·  most recent
@tw-marionette/input Malicious code
15 weekly downloads

MAL-2026-3071 Malicious code in @tw-marionette/input (npm)

input utilities

Blocked 3 versions: 99.0.4 99.0.2 99.0.1
First detected ·  most recent
@tw-models/storage Malicious code
14 weekly downloads

MAL-2026-3072 Malicious code in @tw-models/storage (npm)

storage utilities

Blocked 4 versions: 99.0.4 99.0.3 99.0.2 99.0.1
First detected ·  most recent
@apple-pay-trust/destroy Malicious code
14 weekly downloads

MAL-2026-3317 Malicious code in @apple-pay-trust/destroy (npm)

destroy utilities

Blocked 1 version: 99.0.4
detected
@google-pay-trust/finish Malicious code
14 weekly downloads

MAL-2026-3063 Malicious code in @google-pay-trust/finish (npm)

finish utilities

Blocked 1 version: 99.0.1
detected
@pyme-web/ui-base Malicious code
14 weekly downloads

MAL-2026-3118 Malicious code in @pyme-web/ui-base (npm)

ui-base utilities

Blocked 1 version: 99.0.4
detected
12 weekly downloads

MAL-2026-3068 Malicious code in @sbt_gitverse/analytics-client (npm)

analytics-client utilities

Blocked 4 versions: 99.0.7 99.0.5 99.0.4 99.0.3
First detected ·  most recent
apple-internal-pki-utils Malicious code
12 weekly downloads

MAL-2026-3160 Malicious code in apple-internal-pki-utils (npm)

Blocked 1 version: 1.0.1
detected
@pyme-web/web-api Malicious code
12 weekly downloads

MAL-2026-3120 Malicious code in @pyme-web/web-api (npm)

web-api utilities

Blocked 1 version: 99.0.4
detected
kl-b2c-ui-kit Malicious code
9 weekly downloads

MAL-2026-3082 Malicious code in kl-b2c-ui-kit (npm)

kl-b2c-ui-kit utilities

Blocked 3 versions: 99.0.4 99.0.2 99.0.1
First detected ·  most recent
@tochka-ui/foundation Malicious code
9 weekly downloads

MAL-2026-3069 Malicious code in @tochka-ui/foundation (npm)

gigaid utilities

Blocked 4 versions: 99.0.7 99.0.5 99.0.4 99.0.3
First detected ·  most recent
@pyme-web/ui-widget Malicious code
9 weekly downloads

MAL-2026-3119 Malicious code in @pyme-web/ui-widget (npm)

ui-widget utilities

Blocked 1 version: 99.0.4
detected
9 weekly downloads

MAL-2025-190901 Malicious code in @postman/final-node-keytar (npm)

Bindings to native Mac/Linux/Windows password APIs

Blocked 1 version: 7.9.0
detected
@tw-marionette/clipboard Malicious code
8 weekly downloads

MAL-2026-3070 Malicious code in @tw-marionette/clipboard (npm)

clipboard utilities

Blocked 3 versions: 99.0.4 99.0.2 99.0.1
First detected ·  most recent
@taxmoninor/taxmon Malicious code
8 weekly downloads

MAL-2026-3121 Malicious code in @taxmoninor/taxmon (npm)

taxmon utilities

Blocked 1 version: 99.0.7
detected
apple-internal-dev-check Malicious code
7 weekly downloads

MAL-2026-3124 Malicious code in apple-internal-dev-check (npm)

Blocked 1 version: 2.0.0
detected
5 weekly downloads

MAL-2026-3152 Malicious code in apple-coredata-internal-service (npm)

Internal research utility for infrastructure audit

Blocked 1 version: 1.0.0
detected