← All packages

Supply-chain attacks we’ve detected

Popular npm packages whose release stream was tampered with — either a version OSV confirmed as malicious code, or a version our own analysis flagged as a likely account takeover before any public advisory. None of these versions were ever served from this registry; where the package still has clean releases, those keep flowing.

108
Packages hit
531
Blocked versions
22
Confirmed malware (OSV)
86
Detected before any advisory

Show all · updated

Confirmed malicious releases

Versions OSV’s malicious-packages dataset confirms contained malicious code. We blocked these the moment the advisory landed — or before, then OSV agreed.

fsevents Malicious code clean versions still served
31,737,795 weekly downloads

MAL-2023-462 Malicious code in fsevents (npm)

Native Access to MacOS FSEvents

First detected ·  most recent
fs Malicious code clean versions still served
1,946,205 weekly downloads

MAL-2025-21003 Malicious code in fs (npm)

This package name is not currently in use, but was formerly occupied by another package. To avoid malicious use, npm is hanging on to the package name, but loosely, and we'll probably give it to you if you want it.

Blocked 2 versions: 0.0.2 0.0.0
First detected ·  most recent
@bitwarden/cli Malicious code clean versions still served
71,038 weekly downloads

MAL-2026-3020 Malicious code in @bitwarden/cli (npm)

A secure and free password manager for all of your devices.

Blocked 1 version: 2026.4.0
detected
common-tg-service Malicious code clean versions still served
31,636 weekly downloads

MAL-2026-3288 Malicious code in common-tg-service (npm)

Common Telegram service for NestJS applications

First detected ·  most recent
axis-charts Malicious code
429 weekly downloads

MAL-2026-3077 Malicious code in axis-charts (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
axis-notification Malicious code
428 weekly downloads

MAL-2026-3078 Malicious code in axis-notification (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
axis-ui-generator Malicious code
416 weekly downloads

MAL-2026-3079 Malicious code in axis-ui-generator (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
@clearpool/utils Malicious code
346 weekly downloads

MAL-2026-3059 Malicious code in @clearpool/utils (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 9.9.9
First detected ·  most recent
@tochka-ui/foundation Malicious code
271 weekly downloads

MAL-2026-3069 Malicious code in @tochka-ui/foundation (npm)

gigaid utilities

Blocked 4 versions: 99.0.7 99.0.5 99.0.4 99.0.3
First detected ·  most recent
259 weekly downloads

MAL-2026-3068 Malicious code in @sbt_gitverse/analytics-client (npm)

analytics-client utilities

Blocked 4 versions: 99.0.7 99.0.5 99.0.4 99.0.3
First detected ·  most recent
apcyber-test-package Malicious code
246 weekly downloads

MAL-2026-3304 Malicious code in apcyber-test-package (npm)

Internal automation library.

Blocked 2 versions: 100.0.0 99.99.99
First detected ·  most recent
axis-abc-search-account Malicious code
243 weekly downloads

MAL-2026-3075 Malicious code in axis-abc-search-account (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
axis-abc-portal-menu Malicious code
239 weekly downloads

MAL-2026-3074 Malicious code in axis-abc-portal-menu (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
axis-abc-search-address Malicious code
208 weekly downloads

MAL-2026-3076 Malicious code in axis-abc-search-address (npm)

Internal automation library.

Blocked 3 versions: 100.0.0 99.99.99 1.0.0
First detected ·  most recent
rtms-manager Malicious code
197 weekly downloads

MAL-2026-2862 Malicious code in rtms-manager (npm)

Dependency Confusion poc

Blocked 2 versions: 1.4.0 1.2.0
First detected ·  most recent
apollo-vertex Malicious code
150 weekly downloads

MAL-2026-3040 Malicious code in apollo-vertex (npm)

Blocked 1 version: 1.0.1
detected
apollo-landing Malicious code
148 weekly downloads

MAL-2026-3038 Malicious code in apollo-landing (npm)

Blocked 1 version: 1.0.1
detected
standalone-apps Malicious code
136 weekly downloads

MAL-2026-3037 Malicious code in standalone-apps (npm)

Blocked 1 version: 1.0.1
detected
uipath-ui-widgets Malicious code
135 weekly downloads

MAL-2026-3036 Malicious code in uipath-ui-widgets (npm)

Blocked 1 version: 1.0.1
detected
process-app-task Malicious code
134 weekly downloads

MAL-2026-3039 Malicious code in process-app-task (npm)

Blocked 1 version: 1.0.1
detected
tether-base Malicious code
69 weekly downloads

MAL-2026-3033 Malicious code in tether-base (npm)

Test package for dependency confusion detection

Blocked 1 version: 99.0.0
detected
@alfa.life.mapp/app.web Malicious code
32 weekly downloads

MAL-2026-3052 Malicious code in @alfa.life.mapp/app.web (npm)

app.web utilities

Blocked 3 versions: 99.0.18 99.0.16 99.0.15
First detected ·  most recent