← All packages

Supply-chain attacks we’ve detected

Popular npm packages whose release stream was tampered with — either a version OSV confirmed as malicious code, or a version our own analysis flagged as a likely account takeover before any public advisory. None of these versions were ever served from this registry; where the package still has clean releases, those keep flowing.

108
Packages hit
531
Blocked versions
22
Confirmed malware (OSV)
86
Detected before any advisory

Show OSV-confirmed only · updated

Confirmed malicious releases

Versions OSV’s malicious-packages dataset confirms contained malicious code. We blocked these the moment the advisory landed — or before, then OSV agreed.

fsevents Malicious code clean versions still served
31,737,795 weekly downloads

MAL-2023-462 Malicious code in fsevents (npm)

Native Access to MacOS FSEvents

First detected ·  most recent
fs Malicious code clean versions still served
1,946,205 weekly downloads

MAL-2025-21003 Malicious code in fs (npm)

This package name is not currently in use, but was formerly occupied by another package. To avoid malicious use, npm is hanging on to the package name, but loosely, and we'll probably give it to you if you want it.

Blocked 2 versions: 0.0.2 0.0.0
First detected ·  most recent
@bitwarden/cli Malicious code clean versions still served
71,038 weekly downloads

MAL-2026-3020 Malicious code in @bitwarden/cli (npm)

A secure and free password manager for all of your devices.

Blocked 1 version: 2026.4.0
detected
common-tg-service Malicious code clean versions still served
31,636 weekly downloads

MAL-2026-3288 Malicious code in common-tg-service (npm)

Common Telegram service for NestJS applications

First detected ·  most recent
axis-charts Malicious code
429 weekly downloads

MAL-2026-3077 Malicious code in axis-charts (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
axis-notification Malicious code
428 weekly downloads

MAL-2026-3078 Malicious code in axis-notification (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
axis-ui-generator Malicious code
416 weekly downloads

MAL-2026-3079 Malicious code in axis-ui-generator (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
@clearpool/utils Malicious code
346 weekly downloads

MAL-2026-3059 Malicious code in @clearpool/utils (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 9.9.9
First detected ·  most recent
@tochka-ui/foundation Malicious code
271 weekly downloads

MAL-2026-3069 Malicious code in @tochka-ui/foundation (npm)

gigaid utilities

Blocked 4 versions: 99.0.7 99.0.5 99.0.4 99.0.3
First detected ·  most recent
259 weekly downloads

MAL-2026-3068 Malicious code in @sbt_gitverse/analytics-client (npm)

analytics-client utilities

Blocked 4 versions: 99.0.7 99.0.5 99.0.4 99.0.3
First detected ·  most recent
apcyber-test-package Malicious code
246 weekly downloads

MAL-2026-3304 Malicious code in apcyber-test-package (npm)

Internal automation library.

Blocked 2 versions: 100.0.0 99.99.99
First detected ·  most recent
axis-abc-search-account Malicious code
243 weekly downloads

MAL-2026-3075 Malicious code in axis-abc-search-account (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
axis-abc-portal-menu Malicious code
239 weekly downloads

MAL-2026-3074 Malicious code in axis-abc-portal-menu (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
axis-abc-search-address Malicious code
208 weekly downloads

MAL-2026-3076 Malicious code in axis-abc-search-address (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
rtms-manager Malicious code
197 weekly downloads

MAL-2026-2862 Malicious code in rtms-manager (npm)

Dependency Confusion poc

Blocked 2 versions: 1.4.0 1.2.0
First detected ·  most recent
apollo-vertex Malicious code
150 weekly downloads

MAL-2026-3040 Malicious code in apollo-vertex (npm)

Blocked 1 version: 1.0.1
detected
apollo-landing Malicious code
148 weekly downloads

MAL-2026-3038 Malicious code in apollo-landing (npm)

Blocked 1 version: 1.0.1
detected
standalone-apps Malicious code
136 weekly downloads

MAL-2026-3037 Malicious code in standalone-apps (npm)

Blocked 1 version: 1.0.1
detected
uipath-ui-widgets Malicious code
135 weekly downloads

MAL-2026-3036 Malicious code in uipath-ui-widgets (npm)

Blocked 1 version: 1.0.1
detected
process-app-task Malicious code
134 weekly downloads

MAL-2026-3039 Malicious code in process-app-task (npm)

Blocked 1 version: 1.0.1
detected
tether-base Malicious code
69 weekly downloads

MAL-2026-3033 Malicious code in tether-base (npm)

Test package for dependency confusion detection

Blocked 1 version: 99.0.0
detected
@alfa.life.mapp/app.web Malicious code
32 weekly downloads

MAL-2026-3052 Malicious code in @alfa.life.mapp/app.web (npm)

app.web utilities

Blocked 3 versions: 99.0.18 99.0.16 99.0.15
First detected ·  most recent

Flagged before any public advisory

Popular, previously-trusted packages where a new release set off our analysis or AI reviewer — a new publisher on an old version line, a swapped dependency, a dropped provenance attestation — the patterns real account takeovers leave behind. The reviewer’s own reasoning is shown; clean releases keep flowing.

@babel/traverse Flagged before any advisory clean versions still served
136,357,714 weekly downloads

This version of @babel/traverse has several strong rejection signals: 1.

The Babel Traverse module maintains the overall tree state, and is responsible for replacing, removing, and adding nodes

Blocked 1 version: 8.0.0-beta.4
detected
@noble/curves Flagged before any advisory clean versions still served
18,101,595 weekly downloads

The primary concern here is the regressed provenance finding.

Audited & minimal JS implementation of elliptic curve cryptography

Blocked 1 version: 2.0.0-beta.1
detected
@tanstack/react-router Flagged before any advisory clean versions still served
14,661,480 weekly downloads

This version exhibits the classic supply-chain attack pattern: provenance attestation regressed (prior versions had it), a 2.

Blocked 1 version: 1.169.8+gfinternaltest.1lw2753
detected
engine.io-client Flagged before any advisory clean versions still served
11,949,396 weekly downloads

This is v3.5.6 but the diff baseline is v6.6.3 — a massive version regression on a legacy branch. The provenance attestation is missing when prior versions had it, which is the exact pattern seen in…

Client for the realtime Engine

Blocked 1 version: 3.5.6
detected
jwks-rsa Flagged before any advisory clean versions still served
10,458,134 weekly downloads

Multiple high-severity signals converge to indicate a likely account compromise or unauthorized publish: 1.

Blocked 1 version: 1.12.4
detected
class-validator Flagged before any advisory clean versions still served
9,143,348 weekly downloads

Two converging signals strongly suggest a potential account takeover or unauthorized publish: 1.

Decorator-based property validation for classes.

Blocked 1 version: 0.15.1
detected
@tiptap/extension-horizontal-rule Flagged before any advisory clean versions still served
9,031,308 weekly downloads

Multiple converging signals strongly suggest this version should not be admitted: 1.

Blocked 1 version: 2.27.0
detected
@tiptap/extension-list-item Flagged before any advisory clean versions still served
8,975,617 weekly downloads

Multiple high-severity signals converge here, forming a pattern consistent with a supply chain attack or account compromise: 1.

Blocked 1 version: 2.27.0
detected
@ardatan/relay-compiler Flagged before any advisory clean versions still served
8,404,829 weekly downloads

This version exhibits multiple concerning signals that collectively warrant rejection: 1.

Fork of `relay-compiler`

detected
sanitize-html Flagged before any advisory clean versions still served
7,751,590 weekly downloads

Multiple high-risk signals converge: publisher changed to a new account (boutell, 0 approved / 1 rejected), missing gitHead after previous versions had it, ~6-year dormancy before sudden publish, and…

Clean up user-submitted HTML, preserving allowlisted elements and allowlisted attributes on a per-element basis

Blocked 1 version: 2.17.4
detected
systeminformation Flagged before any advisory clean versions still served
6,870,265 weekly downloads

The publisher "plusinnovations" is a brand-new account (first seen only 46 days ago, 0 packages published, 0 approved/rejected history) publishing a version of the well-established `systeminformation…

Blocked 1 version: 5.31.5
detected
oxlint Flagged before any advisory clean versions still served
6,592,000 weekly downloads

This version exhibits multiple strong indicators of a potentially compromised or unauthorized publish: 1.

Linter for the JavaScript Oxidation Compiler

Blocked 1 version: 1.61.1
detected
@algolia/requester-browser-xhr Flagged before any advisory clean versions still served
6,458,100 weekly downloads

Multiple high-severity signals converge to indicate a likely unauthorized or compromised publish: 1.

Blocked 1 version: 4.26.0
detected
event-stream Flagged before any advisory clean versions still served
6,408,085 weekly downloads

This package is highly suspicious and should be rejected for several reasons: 1.

construct pipes of streams of events

Blocked 2 versions: 4.0.1 3.3.5
First detected ·  most recent
@algolia/client-common Flagged before any advisory clean versions still served
6,352,223 weekly downloads

Multiple HIGH-severity signals converge to paint a very concerning picture consistent with a supply chain attack or account compromise: 1.

Blocked 1 version: 4.26.0
detected
@algolia/client-analytics Flagged before any advisory clean versions still served
6,243,698 weekly downloads

Multiple high-severity signals converge to indicate a likely account takeover or supply chain compromise: 1.

Blocked 1 version: 4.26.0
detected
@algolia/requester-node-http Flagged before any advisory clean versions still served
6,156,295 weekly downloads

Multiple converging high-severity signals strongly suggest this is either an account compromise or unauthorized publish: 1.

Blocked 1 version: 4.27.0
detected
@scure/bip32 Flagged before any advisory clean versions still served
6,100,087 weekly downloads

The sole but significant finding here is a regressed provenance attestation: prior versions of @scure/bip32 were published via CI/CD with provenance attestations, but this version (1.

Secure, audited & minimal implementation of BIP32 hierarchical deterministic (HD) wallets over secp256k1

Blocked 1 version: 1.6.1
detected
@algolia/client-search Flagged before any advisory clean versions still served
6,078,596 weekly downloads

Multiple converging high-severity signals strongly indicate a compromised or unauthorized publish: 1.

Blocked 1 version: 4.27.0
detected
@algolia/client-personalization Flagged before any advisory clean versions still served
5,570,693 weekly downloads

Multiple high-severity signals converge strongly on a likely account compromise or unauthorized publish: 1.

Blocked 1 version: 4.26.0
detected
@algolia/recommend Flagged before any advisory clean versions still served
5,209,435 weekly downloads

Multiple high-severity signals converge to indicate a likely account compromise or unauthorized publish: 1.

Blocked 1 version: 4.27.0
detected
pdf-parse Flagged before any advisory clean versions still served
4,654,713 weekly downloads

This version of pdf-parse@1.

Pure TypeScript, cross-platform module for extracting text, images, and tabular data from PDFs. Run directly in your browser or in Node!

Blocked 1 version: 1.1.2
detected
react-native-reanimated Flagged before any advisory clean versions still served
4,481,904 weekly downloads

Two critical signals combine to make this a strong reject: 1.

More powerful alternative to Animated library for React Native.

Blocked 1 version: 4.1.7
detected
@wdio/types Flagged before any advisory clean versions still served
4,287,214 weekly downloads

Several converging signals make this version suspicious: 1.

Utility package providing type information for a variety of WebdriverIO interfaces

Blocked 1 version: 7.40.0
detected
@langchain/core Flagged before any advisory clean versions still served
4,178,687 weekly downloads

This version of @langchain/core exhibits two HIGH-severity signals that together constitute a strong compromise pattern: 1.

Core LangChain.js abstractions and schemas

Blocked 1 version: 0.3.80
detected
@tiptap/extension-text-style Flagged before any advisory clean versions still served
4,150,961 weekly downloads

Multiple high-severity signals converge to suggest a potential account compromise or unauthorized publish: 1.

Blocked 1 version: 2.27.0
detected
@wdio/utils Flagged before any advisory clean versions still served
3,699,788 weekly downloads

The sole but significant finding here is a regressed provenance attestation: prior versions of @wdio/utils were published via CI/CD with provenance attestations, but this version (9.

A WDIO helper utility to provide several utility functions used across the project.

Blocked 1 version: 9.20.1
detected
openapi-typescript Flagged before any advisory clean versions still served
3,599,745 weekly downloads

This package exhibits multiple red flags that collectively indicate a likely account takeover or malicious repackaging: 1.

Convert OpenAPI 3.0 & 3.1 schemas to TypeScript

Blocked 1 version: 2.2.0
detected
antd Flagged before any advisory clean versions still served
3,473,955 weekly downloads

Critical package identity mismatch: The package being reviewed is listed as `antd@0.

An enterprise-class UI design language and React components implementation

Blocked 2 versions: 1.0.0-beta 0.10.0-beta26
First detected ·  most recent
@tiptap/extension-table Flagged before any advisory clean versions still served
3,175,455 weekly downloads

The single HIGH finding here is significant: this version was published without provenance attestation, while prior versions were published via CI/CD with attestations.

Blocked 1 version: 2.27.2
detected
webdriver Flagged before any advisory clean versions still served
3,118,515 weekly downloads

This version raises significant concern due to the combination of regressed provenance and suspicious version numbering.

A Node.js bindings implementation for the W3C WebDriver and Mobile JSONWire Protocol

Blocked 1 version: 7.40.0
detected
@langchain/openai Flagged before any advisory clean versions still served
2,919,175 weekly downloads

This version raises significant supply-chain integrity concerns: 1.

OpenAI integrations for LangChain.js

Blocked 1 version: 0.6.17
detected
webdriverio Flagged before any advisory clean versions still served
2,869,831 weekly downloads

This version raises multiple red flags that together warrant rejection: 1.

Next-gen browser and mobile automation test framework for Node.js

Blocked 1 version: 7.40.0
detected
@mediapipe/tasks-vision Flagged before any advisory clean versions still served
2,787,850 weekly downloads

Multiple converging signals strongly suggest an account takeover or unauthorized publish rather than a legitimate maintainer transition: 1.

Blocked 1 version: 0.10.32
detected
rc-tabs Flagged before any advisory clean versions still served
2,662,154 weekly downloads

This version exhibits multiple critical red flags that collectively indicate a likely package compromise or malicious injection: 1.

tabs ui component for react

Blocked 2 versions: 9.3.1 9.1.1
First detected ·  most recent
rc-tree-select Flagged before any advisory clean versions still served
2,504,998 weekly downloads

The critical signal here is that the publisher `zombiej` is SPAM-FLAGGED.

tree-select ui component for react

Blocked 1 version: 5.24.5
detected
rc-picker Flagged before any advisory clean versions still served
2,453,977 weekly downloads

The publisher `zombiej` is SPAM-FLAGGED, which is a hard reject signal per the review rubric.

React date & time picker

Blocked 1 version: 4.8.2
detected
rc-switch Flagged before any advisory clean versions still served
2,450,715 weekly downloads

The publisher `zombiej` is SPAM-FLAGGED, which is a hard reject signal per review policy.

switch ui component for react

Blocked 1 version: 3.1.0
detected
rc-cascader Flagged before any advisory clean versions still served
2,439,478 weekly downloads

The publisher `zombiej` is SPAM-FLAGGED, which is a hard reject signal per review policy.

cascade select ui component for react

Blocked 1 version: 3.6.1
detected
perfect-scrollbar Flagged before any advisory clean versions still served
2,426,235 weekly downloads

This version exhibits multiple strong indicators of a potential package takeover: 1.

Minimalistic but perfect custom scrollbar plugin

Blocked 1 version: 1.5.6
detected
babel-generator Flagged before any advisory clean versions still served
2,197,319 weekly downloads

The publisher `amasad` is SPAM-FLAGGED, which is a hard reject signal per policy.

Turns an AST into code.

Blocked 1 version: 6.3.1
detected
expect-webdriverio Flagged before any advisory clean versions still served
1,560,489 weekly downloads

This version (3.

WebdriverIO Assertion Library

Blocked 1 version: 3.7.0
detected
@algolia/logger-console Flagged before any advisory clean versions still served
1,520,675 weekly downloads

Multiple converging signals strongly suggest this version was not published through the normal, trusted CI/CD pipeline: 1.

Blocked 1 version: 4.26.0
detected
isomorphic-git Flagged before any advisory clean versions still served
1,189,848 weekly downloads

The primary concern here is the publisher mismatch.

A pure JavaScript reimplementation of git for node and browsers

Blocked 1 version: 1.37.2
detected
vue-hot-reload-api Flagged before any advisory clean versions still served
1,185,485 weekly downloads

The publisher `soda` is SPAM-FLAGGED, which is a hard reject signal per review policy.

hot reload api for *.vue components

Blocked 1 version: 2.3.4
detected
@noble/secp256k1 Flagged before any advisory clean versions still served
1,136,713 weekly downloads

The single but significant finding here is a regressed provenance attestation: prior versions of @noble/secp256k1 were published via CI/CD with provenance attestations, but this version (2.

Fastest 5KB JS implementation of secp256k1 ECDH & ECDSA signatures compliant with RFC6979

Blocked 1 version: 2.2.2
detected
amazon-cognito-identity-js Flagged before any advisory clean versions still served
1,078,657 weekly downloads

This package exhibits a critical metadata mismatch that indicates a fundamental integrity problem.

Amazon Cognito Identity Provider JavaScript SDK

Blocked 2 versions: 1.9.0 1.8.0
First detected ·  most recent
@aws-amplify/data-schema Flagged before any advisory clean versions still served
1,029,013 weekly downloads

This version exhibits multiple concerning signals that, in aggregate, suggest a potential account compromise or unauthorized package takeover: 1.

Blocked 1 version: 0.0.0-sel-set-20251204071753
detected
grunt-legacy-util Flagged before any advisory clean versions still served
1,019,750 weekly downloads

This version raises multiple red flags that together paint a concerning picture: 1.

Some old grunt utils provided for backwards compatibility.

Blocked 1 version: 2.0.2
detected
inngest Flagged before any advisory clean versions still served
958,611 weekly downloads

This version exhibits a highly suspicious combination of signals that together strongly suggest a compromised or unauthorized publish: 1.

Official SDK for Inngest.com. Inngest is the reliability layer for modern applications. Inngest combines durable execution, events, and queues into a zero-infra platform with built-in observability.

Blocked 1 version: 3.53.1
detected
react-json-tree Flagged before any advisory clean versions still served
922,524 weekly downloads

The package.json declares itself as `[email protected]` (Native Abstractions for Node.js) but is published under the name `[email protected]` — a clear package identity mismatch indicating a hijack or s…

React JSON Viewer Component, Extracted from redux-devtools

Blocked 1 version: 0.10.8
detected
useragent Flagged before any advisory clean versions still served
823,487 weekly downloads

This version is affected by GHSA-mgfv-m47x-4wqp (CVE-2020-26311), a ReDoS vulnerability with CVSS 7.

Fastest, most accurate & effecient user agent string parser, uses Browserscope's research for parsing

Blocked 1 version: 2.3.0
detected
skills Flagged before any advisory clean versions still served
793,857 weekly downloads

Two high-severity provenance signals fire together: prior versions were published via CI/CD with attestations, but this version lacks provenance and was published by a new npm account ("quuu", first…

Blocked 1 version: 1.5.3
detected
fumadocs-core Flagged before any advisory clean versions still served
537,313 weekly downloads

Two HIGH-severity signals align with the axios-style supply chain attack pattern: provenance attestation regressed (prior versions had CI/CD attestations, this one doesn't) and the publisher changed…

Blocked 1 version: 16.8.0
detected
@capacitor/camera Flagged before any advisory clean versions still served
523,719 weekly downloads

Three compounding red flags: publisher changed from `capacitor-plugin-bot` to a new account (`os-pedrobilro`) with zero prior publishes, provenance attestation regressed (prior versions had CI/CD att…

Blocked 1 version: 8.1.0
detected
codecov Flagged before any advisory clean versions still served
476,699 weekly downloads

This is codecov@3.

Uploading report to Codecov: https://codecov.io

Blocked 1 version: 3.7.1
detected
@pnpm/link-bins Flagged before any advisory clean versions still served
474,992 weekly downloads

Two HIGH-severity provenance signals are present and together constitute a strong account-compromise indicator: 1.

Link bins to node_modules/.bin

Blocked 1 version: 1000.3.6
detected
@mui/x-data-grid-premium Flagged before any advisory clean versions still served
470,060 weekly downloads

Three compounding high-severity signals: (1) provenance attestation regressed — prior versions published via CI/CD, this one published manually by `michelengelen`; (2) publisher changed from GitHub A…

Blocked 1 version: 7.29.13
detected
tronweb Flagged before any advisory clean versions still served
457,472 weekly downloads

Multiple converging signals strongly suggest this is a compromised or malicious version of tronweb: 1.

Blocked 1 version: 5.3.5
detected
devtools Flagged before any advisory clean versions still served
456,482 weekly downloads

This version raises significant concerns due to the combination of several signals: 1.

A Chrome DevTools protocol binding that maps WebDriver commands into Chrome DevTools commands using Puppeteer

Blocked 2 versions: 7.40.0 7.35.0
First detected ·  most recent
fumadocs-ui Flagged before any advisory clean versions still served
456,054 weekly downloads

Two high-severity signals converge: provenance attestation regressed (prior versions published via CI/CD with attestations, this one lacks them) and the publisher changed from GitHub Actions to the n…

Blocked 1 version: 16.8.0
detected
npm-lifecycle Flagged before any advisory clean versions still served
447,093 weekly downloads

The publisher `isaacs` is SPAM-FLAGGED, which is a hard reject signal per review policy.

JavaScript package lifecycle hook runner

Blocked 1 version: 3.1.5
detected
@clerk/localizations Flagged before any advisory clean versions still served
432,372 weekly downloads

Multiple converging red flags point to a likely account compromise or supply-chain attack: 1.

Localizations for the Clerk components

Blocked 1 version: 3.37.4
detected
@blueprintjs/core Flagged before any advisory clean versions still served
333,031 weekly downloads

Two converging signals strongly suggest account takeover or unauthorized publish: 1.

Blocked 1 version: 6.12.1
detected
@apollo/query-graphs Flagged before any advisory clean versions still served
296,334 weekly downloads

Two high-severity signals align: provenance attestation regressed (prior versions published via CI/CD, this one is not) and the publisher changed from GitHub Actions to a human account (`dkuc`) on th…

Blocked 1 version: 2.13.2
detected
@clerk/express Flagged before any advisory clean versions still served
215,192 weekly downloads

Multiple converging red flags point to a likely account compromise or hijack rather than a legitimate release: 1.

Clerk server SDK for usage with Express

Blocked 1 version: 1.7.78
detected
bpmn-js Flagged before any advisory clean versions still served
184,718 weekly downloads

Publisher changed from the long-standing `nikku` to `alekseymanetov` (first seen 19 days ago, 0 prior packages), combined with a dormant-publish flag (3680 days of inactivity) and a spam-flagged main…

Blocked 1 version: 18.13.2
detected
@tiptap/extension-focus Flagged before any advisory clean versions still served
176,722 weekly downloads

Two high-severity signals converge: provenance attestation regressed (prior versions had CI/CD attestations; this one doesn't — the exact axios-attack pattern) and the publisher changed from `tiptap-…

Blocked 1 version: 2.27.2
detected
@medplum/core Flagged before any advisory clean versions still served
83,340 weekly downloads

Multiple high-severity signals converge to indicate a likely account compromise or unauthorized publish: 1.

Blocked 1 version: 2.1.26
detected
@medplum/fhirtypes Flagged before any advisory clean versions still served
80,800 weekly downloads

Multiple high-severity signals converge to indicate a likely account compromise or unauthorized publish: 1.

Blocked 1 version: 2.1.26
detected
@clerk/fastify Flagged before any advisory clean versions still served
76,088 weekly downloads

Multiple converging signals raise serious concern about this version: 1.

Clerk SDK for Fastify

Blocked 1 version: 2.6.30
detected
@heroku-cli/color Flagged before any advisory clean versions still served
68,281 weekly downloads

This package is a clear malware/supply chain attack.

Blocked 1 version: 1.1.9
detected
@univerjs-pro/sheets-chart Flagged before any advisory clean versions still served
58,795 weekly downloads

Four newly added facade files (lib/cjs, lib/es, lib/umd, lib/facade.

Chart library for Univer.

Blocked 1 version: 0.21.0
detected
@jupyterlab/fileeditor Flagged before any advisory clean versions still served
38,248 weekly downloads

Several converging signals raise serious concern about this version: 1.

JupyterLab - Editor Widget

Blocked 1 version: 3.6.7
detected
@mapbox/geojsonhint Flagged before any advisory clean versions still served
36,237 weekly downloads

Two HIGH-severity findings flag unclaimed maintainer email domains: `perrygeo@gmail.

validate and sanity-check geojson files

Blocked 1 version: 1.2.1
detected
@jupyterlab/markdownviewer Flagged before any advisory clean versions still served
24,521 weekly downloads

The dominant signal here is the HIGH-severity `regressed-provenance` finding: prior versions of this package were published with CI/CD provenance attestations, but this version (3.

Blocked 1 version: 3.6.7
detected
art-template Flagged before any advisory clean versions still served
22,532 weekly downloads

Multiple converging signals strongly indicate a package takeover/hijack: 1.

JavaScript Template Engine

Blocked 1 version: 4.13.3
detected
@tiptap/extension-details-content Flagged before any advisory clean versions still served
22,234 weekly downloads

Provenance attestation is missing on this version despite prior versions being published via CI/CD with attestations — a pattern matching the axios supply-chain attack.

Blocked 1 version: 2.26.3
detected
@feathersjs/authentication-oauth Flagged before any advisory clean versions still served
20,547 weekly downloads

Three HIGH-severity OSV advisories affect this version (4.

Blocked 1 version: 4.5.19
detected
camaro Flagged before any advisory clean versions still served
16,067 weekly downloads

Multiple converging signals strongly suggest this version is suspicious and potentially the result of an account compromise or unauthorized publish: 1.

Transforming XML to JSON using Node.js binding to native pugixml parser library

Blocked 1 version: 3.0.20
detected
@cleocode/lafs Flagged before any advisory clean versions still served
10,189 weekly downloads

Two HIGH-severity provenance findings combine into a strong rejection signal: 1.

LLM-Agent-First Specification schemas and conformance tooling

Blocked 1 version: 2026.4.11
detected
@microsoft/node-core-library Flagged before any advisory clean versions still served
9,840 weekly downloads

This version exhibits a highly suspicious combination of signals that together strongly suggest a package hijack or malicious redirect: 1.

(Please use "@rushstack/node-core-library" instead.)

Blocked 1 version: 4.0.1
detected
@cleocode/agents Flagged before any advisory clean versions still served
7,417 weekly downloads

Two HIGH-severity provenance findings combine into a strong rejection signal: 1.

CLEO agent protocols and templates

Blocked 1 version: 2026.4.0
detected
@insforge/sdk Flagged before any advisory clean versions still served
7,030 weekly downloads

Multiple converging signals strongly suggest a compromised or unauthorized publisher takeover: 1.

Blocked 1 version: 1.2.3
detected
discord-protos Flagged before any advisory clean versions still served
6,905 weekly downloads

Multiple high-severity signals converge to paint a concerning picture for this version: 1.

A parser for Discord's protobufs

Blocked 1 version: 1.2.117
detected
@cleocode/contracts Flagged before any advisory clean versions still served
5,528 weekly downloads

Two HIGH-severity provenance findings combine into a strong rejection signal: 1.

Domain types, interfaces, and contracts for the CLEO ecosystem

Blocked 1 version: 2026.4.13
detected