78 THREATS HIGH Published Comprehensive Report

npm Supply Chain Attacks 2026: The Definitive Record of Every Documented Compromise

19 min read
npm supply chain attacksshai-huludslopsquattingbinding.gypdprkteampcpnpm wormaxiosmastraasyncapisoftware supply chain

Between February 1 and July 15, 2026, Threadlinqs Intelligence documented 78 npm supply chain attacks spanning 218 malicious npm packages — self-replicating worms, CI/CD pipeline hijacks, AI-agent credential theft, and industrialized DPRK campaigns. Two throughlines dominate the window: a single crimeware crew, TeamPCP, linked to 40 of the 78 threats through the Shai-Hulud worm lineage, and North Korea, behind 23. This is the full reference: every wave, every technique, and every documented package, each mapped back to its threat record and attributed actor.

npm supply chain attacks by the numbers

78
npm supply-chain threats
218
compromised packages
23
DPRK-attributed (29%)
12
threat actors tracked
702
detection rules
Threats per month, by attribution
DPRKFinancially motivatedUnattributed
01020Feb: 1 unattributedFeb: 1 DPRK2Mar: 3 financially motivatedMar: 4 DPRK7Apr: 1 unattributedApr: 5 financially motivatedApr: 7 DPRK13May: 9 unattributedMay: 4 financially motivatedMay: 1 DPRK14Jun: 12 unattributedJun: 5 financially motivatedJun: 6 DPRK23Jul: 14 unattributedJul: 1 financially motivatedJul: 4 DPRK19FebMarAprMayJunJul
Nation-state activity leads early; unattributed crimeware and worms dominate the later months. July is partial (through the 15th).
Cumulative compromised packages
050100150200Feb: 0 cumulative packages0Mar: 39 cumulative packages39Apr: 56 cumulative packages56May: 102 cumulative packages102Jun: 180 cumulative packages180Jul: 218 cumulative packages218FebMarAprMayJunJul
Distinct npm packages with at least one documented malicious version, accumulating to 218 across the window.

Timeline: the major npm supply chain attacks of 2026

DateWaveThreatsWhat happened
Mar 2026PolinRider VS Code auto-run + blockchain dead-dropsTL-2026-0437DPRK implants spread across 1,951 GitHub repos via Tailwind/PostCSS typosquats and weaponized .vscode/tasks.json, resolving C2 from TRON/Aptos/BSC blockchains.
2026-03-11prt-scan GitHub Actions pwn-request campaignTL-2026-0318One actor with six disposable accounts opened malicious PRs against 500+ repos to exploit pull_request_target and exfiltrate CI/CD secrets in public logs (ran through Apr 3).
Apr 2026Axios compromise by UNC1069 / Sapphire SleetTL-2026-0305, TL-2026-0311, TL-2026-0397, TL-2026-0351A stolen legacy token honored over OIDC published backdoored axios via phantom dependency plain-crypto-js (~600K downloads in 3h); reached OpenAI's macOS signing pipeline, forcing cert rotation. CISA alert 04-20.
Apr 2026TeamPCP cascading Bitwarden/Checkmarx breachTL-2026-0425, TL-2026-0429Reused credentials from the Checkmarx breach poisoned checkmarx/ast-github-action to publish trojanized @bitwarden/cli, harvesting live vault exports and AI-tool configs. CISA AA26-115A.
Apr 2026Mini Shai-Hulud worm: SAP, Intercom, TanStack, @antvTL-2026-0439, TL-2026-0446, TL-2026-0499, TL-2026-0530, TL-2026-0547TeamPCP worm hit SAP CAP, intercom-client, @tanstack/react-router (~12M wk dl) and 200+ @antv packages using Bun-runtime execution, orphan-commit staging and OIDC token theft.
May 2026node-ipc backdoor + Megalodon mass-repo wormTL-2026-0518, TL-2026-0556, TL-2026-0557node-ipc backdoor (require-triggered, DNS-TXT exfil); Megalodon pushed workflow-injection commits to 5,561 GitHub repos in 6 hours, bleeding into npm via @tiledesk/tiledesk-server.
May 2026Cross-ecosystem stealers + cloud-secret typosquatsTL-2026-0576, TL-2026-0623, TL-2026-0633TrapDoor coordinated 34 packages across npm/PyPI/crates.io with zero-width AI-assistant injection; Microsoft flagged typosquat and dependency-confusion packages sweeping AWS/Vault/CI secrets.
May 2026AI becomes a target: Claude sandbox + Codex/MCPTL-2026-0621, TL-2026-0641, TL-2026-0712AI-generated "Malware-Slop" exfiltrated Claude's /mnt/user-data sandbox; codexui-android stole Codex OAuth tokens; a Mitiga PoC hijacked Claude Code MCP traffic for OAuth theft.
Jun 2026Miasma resurgence: RedHat, Microsoft repos, Phantom GypTL-2026-0643, TL-2026-0733, TL-2026-1234, TL-2026-0963, TL-2026-1293TeamPCP's Miasma worm poisoned @redhat-cloud-services and 73 Microsoft repos, introduced the binding.gyp "Phantom Gyp" vector (57 pkgs/286 versions) and abused the npm bypass_2fa API.
2026-06-17Mastra AI-framework mass-republishTL-2026-0898, TL-2026-0836, TL-2026-0977Sapphire Sleet hijacked the dormant ehindero account and republished 140+ @mastra packages (@mastra/core ~918K wk dl) in an ~88-minute burst, injecting the easy-day-js typosquat dependency.
Jun 2026Injective SDK wallet backdoor + Atomic Arch AUR pivotTL-2026-1153, TL-2026-1149, TL-2026-0788, TL-2026-097918 @injectivelabs packages backdoored to steal BIP-39 mnemonics via fake telemetry and HTTP-header exfil; Atomic Arch hijacked 400+ AUR packages to pull malicious npm packages with an eBPF rootkit.
Jun–Jul 2026PolinRider cross-ecosystem expansionTL-2026-1055, TL-2026-1120, TL-2026-1143, TL-2026-1215DPRK PolinRider scaled to 108 malicious packages/extensions (162 artifacts) across npm, Packagist, Go and the Chrome Web Store, with blockchain dead-drop C2 and build-config injection persistence.
Jul 2026AsyncAPI pwn-request → SLSA-signed MiasmaTL-2026-1360, TL-2026-1299, TL-2026-1320, TL-2026-1387An unpatched pull_request_target flaw stole the asyncapi-bot PAT; the project's own OIDC trusted-publishing shipped five malicious @asyncapi versions (~2.9M wk dl) with valid provenance, delivering Miasma at import time.
2026-07-11jscrambler / IronWorm security-vendor compromiseTL-2026-1379, TL-2026-1233, TL-2026-1238A stolen credential published five malicious jscrambler versions (8.14.0–8.20.0) dropping IronWorm, a Rust cross-platform stealer in the Shai-Hulud lineage; flagged in 6 minutes yet republished over 3 hours.
Jul 2026Ecosystem response + AI-native researchTL-2026-1163, TL-2026-1164npm 12 disabled lifecycle scripts, node-gyp, Git deps and remote tarballs by default (opt-in allowlist); researchers demonstrated HalluSquatting, pre-registering LLM-hallucinated names that nine AI coding assistants fetch.

How npm supply chain attacks changed in 2026: the novel techniques

The window's defining shift is that npm stopped being a place where attackers drop a single poisoned package and wait. It became a medium for self-propagating malware, a lever on the pipelines that publish, and a channel to reach AI agents. Eight technique families account for nearly everything documented.

Self-replicating npm worms — the Shai-Hulud lineage

For most of npm's history a compromise was a discrete event: one package, one bad version, one takedown. That model broke down with the Shai-Hulud worm family — the original Shai-Hulud first appeared in late 2025, and Mini Shai-Hulud, Miasma, Hades, and the compiled IronWorm escalated it sharply across this window — worms that harvest cloud and CI credentials at install time and then auto-republish through the very maintainers they just robbed. Socket and StepSecurity tracked the worm family to a crew tracked as TeamPCP, which Threadlinqs links to 40 of the 78 threats in the window; the Shai-Hulud and Miasma generations are carried as distinct operator labels within that lineage rather than as confirmed TeamPCP aliases.

The novelty is closed-loop propagation. Each generation kept the harvest-and-republish core while iterating tradecraft: Bun-runtime execution to sidestep Node tooling, orphan-commit payload staging so the malicious code never appears in the visible Git history, and TruffleHog secret sweeps across the compromised host. Miasma trojanized 57 npm packages across 286+ versions using a 157-byte binding.gyp "Phantom Gyp" that runs a 4–5MB ROT-N-obfuscated index.js during install, harvests AWS/GCP/Azure/Vault/Kubernetes/GitHub-Actions credentials, then propagates across CI/CD (TL-2026-1234). By July the lineage had crossed into compiled Rust with IronWorm (TL-2026-1379), hardening the payload against JavaScript-level scanners entirely.

Install-time and import-time execution without a visible install script

Attackers systematically abandoned the obvious postinstall hook — the first thing any scanner checks — for triggers that evade install-script analysis. Phantom Gyp is the standout: drop a binding.gyp into a pure-JS package and npm invokes node-gyp, whose command-substitution syntax executes code with no lifecycle script declared at all. Others moved execution into module require()/import (with sideEffects arrays to defeat tree-shaking), into preinstall so theft fires before code even unpacks, or into a downloaded Bun runtime that never touches Node-level tooling.

node-ipc 9.1.6/9.2.3/12.0.1 (~822K weekly downloads) fired its credential stealer on module require() rather than any lifecycle script, exfiltrating cloud, SSH, Kubernetes, and Terraform secrets over DNS TXT queries (TL-2026-0518). This pressure was the direct cause of npm 12 flipping lifecycle scripts, node-gyp, Git dependencies, and remote tarballs to opt-in (TL-2026-1163).

CI/CD trusted publishing as the new blast radius

The highest-leverage attacks stopped stealing npm tokens and hijacked the pipelines that publish. The recurring primitive is the GitHub Actions "pwn-request": a pull_request_target workflow that checks out untrusted PR code while holding base-repo secrets. From there, operators read OIDC tokens out of runner memory (/proc/<pid>/mem) and publish through the project's own trusted-publisher workflow — so the poisoned tarball carries valid SLSA provenance.

The AsyncAPI compromise is the clean example: an unpatched pull_request_target flaw leaked the asyncapi-bot PAT, then npm OIDC trusted publishing shipped five malicious @asyncapi versions (~2.9M weekly downloads) with provenance attesting the workflow, not the malicious commit (TL-2026-1360, TL-2026-1299). Automated worms weaponized the same primitive at scale: Megalodon touched 5,561 repos in six hours (TL-2026-0556) and a poisoned codfish/semantic-release-action exposed 1,442 repos. The Axios compromise took a different route — a stolen legacy NPM_TOKEN published the backdoor, which then reached OpenAI's macOS signing pipeline through a floating ^1.14.0 version range in the signing CI (TL-2026-0351), forcing an Apple Developer ID certificate rotation.

AI as both target and weapon

2026 is where AI entered the supply chain from both directions at once. As a target, AI-agent credentials and configs became the prize: OpenAI Codex OAuth tokens, Claude Code MCP OAuth bearer tokens, the Claude sandbox filesystem, and whole frameworks (Mastra, @mistralai). A Mitiga PoC's postinstall hook rewrote mcpServers URLs in ~/.claude.json to route Claude Code's MCP traffic through an attacker mitmproxy, seeded directory-trust flags, and injected a SessionStart hook to steal persistent OAuth bearer tokens for Jira and GitHub over MCP (TL-2026-0712).

As a weapon, AI generated the malware ("slop" packages, language-aware payloads), pre-registered the plausible package names that LLMs hallucinate so coding agents fetch them — a technique now called slopsquatting or HalluSquatting — and manipulated the LLM reviewers themselves. The package shai_hulululud embedded a fake SYSTEM-OVERRIDE prompt-injection and token-flooding to blind LLM scanners (TL-2026-0829). Socket, which first flagged the package, detailed the same prompt-injection technique. It is defense being attacked at its own layer.

Maintainer-trust and account-takeover tradecraft

Rather than exploit code, attackers exploited the trust model around publishing. Documented techniques include a stolen legacy NPM_TOKEN being honored over OIDC Trusted Publishing (bypassing 2FA), dormant contributor access that was never revoked, expired recovery-domain re-registration, social-engineered maintainer handovers, and abuse of the npm bypass_2fa API.

Nearly universal was "phantom-dependency injection" paired with "clean-decoy pre-staging": leave the trusted package's own code untouched and hide the malice one hop away, in a freshly added dependency whose benign decoy version was published hours earlier to defeat novelty heuristics. Backdoored axios@1.14.1/0.30.4 were bit-for-bit identical to the clean releases except one package.json line adding phantom dependency plain-crypto-js@^4.2.1, whose clean 4.2.0 decoy had been staged roughly 18 hours earlier; the maintainer's stolen legacy token was honored over OIDC despite MFA (TL-2026-0305, TL-2026-0397).

Novel C2 and exfiltration channels

Operators fled takedown-prone domains for infrastructure that is immutable, decentralized, or indistinguishable from legitimate traffic. Blockchain dead-drops resolved C2 that cannot be seized: PolinRider's tailwind-color-shades/safe-validate loaders queried TRON and Aptos and decrypted an XOR payload from Binance Smart Chain burn-address transactions — "EtherHiding" — to resolve C2 with no static domain (TL-2026-1215). Legitimate services became payload hosts (Hugging Face, IPFS, GitHub Releases and the Contents API, jsonkeeper and rentry pastes).

Exfiltration hid where egress filters do not look. The @injectivelabs backdoor base64-encoded stolen BIP-39 mnemonics into the X-Request-Id HTTP header, shaped to resemble gRPC-Web traffic (TL-2026-1149). Others used DNS TXT queries, WebRTC P2P, and Cloudflare Worker proxies to survive egress filtering.

DPRK industrialization of developer-targeting campaigns

North Korea moved from bespoke drops to automated malware factories. The Contagious Interview, PolinRider, and WageMole clusters mass-produced malicious packages in escalating waves — 67, then 108-package/261-version runs, then ~200-package OtterCookie batches — delivered through fake-recruiter coding-assessment lures on LinkedIn, Fiverr, and Upwork, plus brandjacking, VS Code tasks.json folderOpen auto-run, malicious git pre-commit hooks, and backdoored IDE-marketplace extensions.

PolinRider published 108 malicious packages and extensions across 162 artifacts spanning npm, Packagist, 80+ Go modules, and the Chrome Web Store, appending obfuscated JS to build-config files (tailwind.config.js, next.config.mjs) and abusing .vscode/tasks.json runOn: folderOpen to auto-run BeaverTail/InvisibleFerret the moment a repo opened (TL-2026-1055, TL-2026-1143). DPRK accounts drove 23 of the 78 threats, and the crypto-theft subset (UNC1069 and PolinRider) went straight for wallet keys.

Typosquatting, dependency-confusion, and cross-ecosystem registry abuse

The classic name-based vectors persisted but grew more sophisticated: inflated version numbers to win dist-tag resolution, brandjacking via suffix or embedding rather than raw typos, dependency-confusion against real internal corporate namespaces, and coordination across npm, PyPI, crates.io, Go, and the AUR under one toolchain. Two newer twists stand out. The Atomic Arch campaign legitimately adopted 400+ (later 1,500+) orphaned AUR packages and modified their PKGBUILD hooks to run npm install atomic-lockfile@1.4.2, whose preinstall hook executes a bundled Rust ELF that steals credentials and installs an eBPF rootkit — a Linux distro repo bridged into npm (TL-2026-0788, TL-2026-0979). Separately, operators abused the npm registry itself as a free CDN, hosting adware and DDoS-botnet payloads in packages with no install hook at all.

Who is behind the npm supply chain attacks?

North Korea dominates. Of the 78 threats, 23 (29%) are DPRK-attributed; of the 41 with a named actor, 23 (56%) trace to DPRK clusters. The rest of the attributed set is financially motivated crimeware, and 37 threats carry no confident attribution at all.

Who is behind them
DPRK: 23 of 78 (29%)Financially motivated: 18 of 78 (23%)Unattributed: 37 of 78 (47%)78threats
DPRK — 23 (29%)Financially motivated — 18 (23%)Unattributed — 37 (47%)

The DPRK clusters overlap by design. Lazarus Group carries the most links (18 threats), reflecting its role as the umbrella under which the sub-clusters operate. Contagious Interview (11 threats) runs the fake-recruiter coding-assessment lures. WageMole (10) handles the IT-worker fraud angle. UNC1069 — the Sapphire Sleet cluster — and APT38 (9 each) drive the financially motivated theft, with UNC1069 behind the Axios and Mastra compromises. PolinRider (4) is the crypto-theft and cross-ecosystem specialist. The unifying motive is money — cryptocurrency wallet keys and developer credentials that convert to access — not espionage in the traditional sense.

The financially motivated crimeware side is defined by one crew. TeamPCP is the single biggest throughline in the entire dataset, linked to 40 threats via the self-replicating worm family. Where DPRK mass-produces discrete packages, TeamPCP built self-propagating malware — the difference between a factory and a contagion. The Shai-Hulud operators (4) and Miasma operators (3) are tracked as related-but-distinct labels for generations of the same lineage. ShinyHunters (15) surfaces around the data-theft and extortion tail, and TrapDoor and PhantomRaven (1 each) round out the cross-ecosystem crypto-stealer crews.

Most active actors, by documented threats
DPRK clusterFinancially motivated
TeamPCPTeamPCP: 4040Lazarus GroupLazarus Group: 1818ShinyHuntersShinyHunters: 1515Contagious InterviewContagious Interview: 1111WageMoleWageMole: 1010UNC1069UNC1069: 99APT38APT38: 99PolinRiderPolinRider: 44
Counts span the full Threadlinqs corpus, not only npm. TeamPCP’s worm lineage is the single largest throughline.

Attribution here is provisional. Worms muddy it further: once a self-propagating payload harvests one maintainer's token and republishes, the "actor" behind a given malicious version may be an automated loop rather than a human operator making a decision. Treat the named-actor column in the master list as an assessment, not a verdict.

How to detect and prevent npm supply chain attacks

The following detections are drawn from the Threadlinqs platform and map to the threats above. Trim the field names to your schema.

Mini Shai-Hulud fires its payload from a lifecycle hook spawning node/bun/python on a staged script — the earliest observable in the kill chain (TL-2026-0446):

sigmatitle: Mini Shai-Hulud npm/pip Preinstall Hook Spawns node-bun on setup.mjs or router_runtime.js
status: experimental
description: Detects npm/yarn/pnpm/pip lifecycle hooks invoking node, bun, or python on
  setup.mjs, router_runtime.js, or the Mini Shai-Hulud trojanized packages (intercom-client,
  @cap-js/*, mbt, lightning).
references:
    - https://socket.dev/blog/intercom-s-npm-package-compromised-in-supply-chain-attack
logsource:
    category: process_creation

The credential sweep that follows install — a node/bun process reading .npmrc, .aws/credentials, .kube/config, .vault-token, and terraform.tfstate within minutes of an install firing (TL-2026-0446):

kqllet credPaths = dynamic([".npmrc", ".yarnrc", "hosts.yml", ".docker/config.json",
    ".aws/credentials", ".kube/config", ".vault-token", ".env", ".envrc",
    "terraform.tfstate", ".gitconfig"]);
DeviceFileEvents
| where Timestamp > ago(24h)
| where ActionType in ("FileAccessed", "FileOpened", "FileRead")
| where InitiatingProcessFileName has_any ("node", "node.exe", "bun", "bun.exe",
    "python", "python3", "npm", "npm.cmd")
| where FileName has_any (credPaths)

Worm propagation is visible as a burst of patch-version publishes from a maintainer dormant for 30+ days, or GitHub repos created with the worm's signature description (TL-2026-0446):

kqllet poisonRepoPrefixes = dynamic(["ghola-melange-", "mentat-melange-", "powindah-sietch-"]);
let poisonDescription = "A Mini Shai-Hulud has Appeared";
GitHubAuditLog_CL
| where TimeGenerated > ago(24h)
| where action_s in ("repo.create", "repo.transfer", "public_repo.create")
| extend RepoName = tostring(repo_s), Description = tostring(description_s)
| where Description has poisonDescription
   or RepoName startswith_cs "ghola-melange-"

For the AI-agent surface, watch MCP config files in AI coding-assistant directories for injection (TL-2026-0147):

kqlDeviceFileEvents
| where Timestamp > ago(24h)
| where FolderPath has_any (".claude", ".cursor", ".continue", ".codeium", ".windsurf")
| where FileName in~ ("settings.json", "mcp.json", "config.json", "mcp_config.json")
| where ActionType in ("FileCreated", "FileModified")

And the exfil tail — Node fetching Pastebin raw URLs mid-install as a dead-drop C2 resolver (TL-2026-0152):

splindex=proxy sourcetype="bluecoat:proxysg:access:syslog" OR sourcetype="squid:access"
| search cs_host="pastebin.com" cs_uri_path="/raw/*"
| eval is_known_deaddrop=if(match(cs_uri_path, "(CJ5PrtNk|0ec7i68M|DjDCxcsT)"), 1, 0)
| stats count as paste_fetches, sum(is_known_deaddrop) as known_hits by src_ip, cs_User_Agent
| where paste_fetches >= 1

Beyond detection, the hygiene that would have blunted most of this window:

Every documented npm package: the master list

The table below is the full package-level record for the window — every documented malicious package and version, sorted by TL number, each row linking to its threat and enriched with the attributed actor and that actor's country and motive. Use it as a blocklist source and a triage reference; the "Actor" column is an assessment, not a confirmed verdict.

Largest namespace compromises
@emilgroup@emilgroup: 2828@injectivelabs@injectivelabs: 1818@antv@antv: 55@tanstack@tanstack: 44@redhat-cloud-services@redhat-cloud-services: 44@asyncapi@asyncapi: 44@mastra@mastra: 44
@emilgroup (CanisterWorm) and @injectivelabs (wallet-key backdoor) are the widest single-namespace hits in the window.
308 rows · 218 packages · 67 threats
TL #PublishedPackage VulnerableFixedPatchedVendor / namespace Threat actorCountryMotiveActor threats
TL-2026-02312026-03-15@aifabrix/miso-client4.7.2—✗@aifabrixPhantomRavenUnknown (cybercrime)Financial (credential theft)1
TL-2026-02312026-03-15@iflow-mcp/watercrawl-watercrawl-mcp1.3.0-1.3.4—✗@iflow-mcpPhantomRavenUnknown (cybercrime)Financial (credential theft)1
TL-2026-02592026-03-20@emilgroup/account-sdk1.41.1, 1.41.2—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/account-sdk-nodepatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/accounting-sdk-nodepatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/api-documentationpatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/auth-sdkpatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/auth-sdk-nodepatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/billing-sdkpatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/billing-sdk-nodepatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/claim-sdkpatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/claim-sdk-nodepatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/customer-sdkpatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/customer-sdk-nodepatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/document-sdkpatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/document-sdk-nodepatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/gdv-sdkpatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/insurance-sdkpatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/insurance-sdk-nodepatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/notification-sdk-nodepatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/partner-portal-sdk-nodepatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/partner-sdk-nodepatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/payment-sdkpatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/payment-sdk-nodepatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/process-manager-sdk-nodepatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/public-api-sdkpatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/public-api-sdk-nodepatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/tenant-sdkpatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/tenant-sdk-nodepatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/translation-sdk-nodepatch .x.1, .x.2 versions—✗emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@teale.io/eslint-config1.8.9, 1.8.10—✗teale.ioTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02792026-03-24ast-github-actionv2.3.28—✗CheckmarxTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02792026-03-24kics-github-actionv1.1—✗CheckmarxTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02792026-03-24setup-trivy0.2.0-0.2.6 (original)0.2.6 (recreated)✓Aqua SecurityTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02792026-03-24trivy-action0.0.1-0.34.2 (76 tags)0.35.0✓Aqua SecurityTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-03002026-03-30axios1.14.1, 0.30.41.14.0, 0.30.3✓axiosUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03002026-03-30plain-crypto-js4.2.1—✗nrwiseUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03012026-03-31@qqbrowser/openclaw-qbot0.0.130—✗qqbrowserUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03012026-03-31@shadanai/openclaw2026.3.28-2, 2026.3.28-3, 2026.3.31-1, 2026.3.31-2—✗shadanaiUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03012026-03-31axios1.14.1, 0.30.41.14.0, 0.30.3✓axiosUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03012026-03-31plain-crypto-js4.2.1—✗nrwiseUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03032026-03-31@qqbrowser/openclaw-qbot0.0.130Package reported for removal✓npmUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03032026-03-31@shadanai/openclaw2026.3.28-2, 2026.3.28-3, 2026.3.31-1, 2026.3.31-2Package reported for removal✓npmUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03032026-03-31axios1.14.1, 0.30.4All other versions (malicious versions unpublished)✓axiosUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03032026-03-31plain-crypto-js4.2.1Package removed from npm✓npmUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03052026-03-31@qqbrowser/openclaw-qbot0.0.130—✗npmUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03052026-03-31@shadanai/openclaw2026.3.31-1, 2026.3.31-2—✗npmUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03052026-03-31axios1.14.1, 0.30.41.14.2, 1.14.0, 0.30.3✓axiosUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03052026-03-31plain-crypto-js4.2.1—✗npmUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03092026-04-01axios1.14.1, 0.30.41.14.0, 0.30.3✓axiosUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03092026-04-01plain-crypto-jsallremoved from npm✓unknownUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03112026-04-01@qqbrowser/openclaw-qbot0.0.130—✗npmAPT38North Korea (DPRK)Financial theft9
TL-2026-03112026-04-01@shadanai/openclaw2026.3.28-2, 2026.3.28-3, 2026.3.31-1, 2026.3.31-2—✗npmAPT38North Korea (DPRK)Financial theft9
TL-2026-03112026-04-01axios1.14.1, 0.30.41.14.2, 0.30.3✓axiosAPT38North Korea (DPRK)Financial theft9
TL-2026-03112026-04-01plain-crypto-js4.2.1—✗npmAPT38North Korea (DPRK)Financial theft9
TL-2026-03142026-04-02axios1.14.1, 0.30.41.14.2, 0.30.5✓axiosUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03142026-04-02plain-crypto-js4.2.1—✗npmUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03322026-04-07express-session-js——✓—Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-03322026-04-07graphalgo——✓—Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-03322026-04-07react-plaid-sdk——✓—Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-03512026-04-11axios1.14.1, 0.30.41.14.0, 0.30.3✓axiosUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03512026-04-11plain-crypto-js4.2.1, 4.2.0—✗Unknown (malicious)UNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03972026-04-20axios1.14.1, 0.30.41.14.0, 0.30.3✓AxiosUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03972026-04-20plain-crypto-js4.2.1, 4.2.00.0.1-security.0 (npm security-holder stub)✓nrwise (attacker-controlled)UNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-04252026-04-27@bitwarden/cli2026.4.72026.4.8, 2026.4.6✓BitwardenTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04292026-04-27@bitwarden/cli2026.4.02026.4.1✓BitwardenTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04372026-04-29tailwind-animationbasedall—✗npm Inc. (registry)PolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-04372026-04-29tailwind-autoanimation2.3.6—✗npm Inc. (registry)PolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-04372026-04-29tailwind-mainanimation2.3.3—✗npm Inc. (registry)PolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-04372026-04-29tailwindcss-animate-styleall—✗npm Inc. (registry)PolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-04372026-04-29tailwindcss-style-animate1.1.6—✗npm Inc. (registry)PolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-04372026-04-29tailwindcss-style-modify0.8.3—✗npm Inc. (registry)PolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-04372026-04-29tailwindcss-typography-style0.8.2—✗npm Inc. (registry)PolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-04392026-04-30@cap-js/db-service2.10.1—✗SAP cap-jsTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04392026-04-30@cap-js/postgres2.2.2—✗SAP cap-jsTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04392026-04-30@cap-js/sqlite2.2.2—✗SAP cap-jsTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04392026-04-30mbt1.2.48—✗—TeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04462026-04-30@cap-js/db-service2.10.1post-2.10.1✓SAPTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04462026-04-30@cap-js/postgres2.2.2post-2.2.2✓SAPTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04462026-04-30@cap-js/sqlite2.2.2post-2.2.2✓SAPTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04462026-04-30intercom-client7.0.47.0.5+✓IntercomTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04462026-04-30lightning2.6.2, 2.6.32.6.1, 2.6.4+✓Lightning AITeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04462026-04-30mbt1.2.48—✗—TeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04992026-05-12@mistralai/mistralai2.2.2, 2.2.3, 2.2.4—✗Mistral AITeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04992026-05-12@tanstack/react-router1.169.5, 1.169.8—✗TanStackTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04992026-05-12guardrails-ai0.10.1—✗Guardrails AITeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04992026-05-12mistralai2.4.6—✗Mistral AITeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05182026-05-15node-ipc9.1.6, 9.2.3, 12.0.1any clean release reverted post-incident; pin to <= 9.2.2 or >= 12.0.2 with verified integrity hash✓node-ipc maintainers (npm)Unattributed———
TL-2026-05282026-05-18@deadcode09284814/axios-util——✗@deadcode09284814Unattributed———
TL-2026-05282026-05-18axois-utils——✗—Unattributed———
TL-2026-05282026-05-18chalk-tempalte——✗—Unattributed———
TL-2026-05282026-05-18color-style-utils——✗—Unattributed———
TL-2026-05302026-05-19@antv/component2.2.11—✗@antvTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05302026-05-19@antv/g25.5.8—✗@antvTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05302026-05-19@antv/g65.2.1—✗@antvTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05302026-05-19@antv/mcp-server-chart0.10.10—✗@antvTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05302026-05-19@antv/util3.4.11—✗@antvTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05302026-05-19nrwl.angular-console18.95.018.94.x or post-incident >= 18.96.0✓NrwlTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05472026-05-21@tanstack/react-router1.169.5, 1.169.81.169.9+✓TanStackTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05472026-05-21@tanstack/router-core1.169.5, 1.169.81.169.9+✓TanStackTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05472026-05-21@tanstack/solid-router1.169.5, 1.169.81.169.9+✓TanStackTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05472026-05-21@tanstack/vue-router1.169.5, 1.169.81.169.9+✓TanStackTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05562026-05-21@tiledesk/tiledesk-server2.18.6, 2.18.7, 2.18.8, 2.18.9, 2.18.10, 2.18.11, 2.18.12—✗TiledeskUnattributed———
TL-2026-05592026-05-22pinno-loggersall published versions—✗npm registry (OpenJS / GitHub)Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-05592026-05-22pretty-logger-utilsall published versions—✗npm registry (OpenJS / GitHub)Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-05592026-05-22terminal-logger-utilsall published versions—✗npm registry (OpenJS / GitHub)Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-05592026-05-22ts-logger-packall published versions—✗npm registry (OpenJS / GitHub)Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-05682026-05-22art-template4.13.3, 4.13.5, 4.13.6, 4.13.44.13.2 (last known clean release, 2018-11-13)✓aui (original) / daughtrymom + npmpacketmaintainmember7 (npm hijacker)Unattributed———
TL-2026-05762026-05-24crates.io6 Sui/Move-themed cratescrates yanked✓Rust FoundationTrapDoorUnknown (cybercrime)Financial (crypto wallet theft)1
TL-2026-06082026-05-27forge-jsx1.0.0 through 1.0.66 (66 versions, all malicious)Replaced by npm security placeholder on 2026-05-04✓npm RegistryUnattributed———
TL-2026-06082026-05-27forge-jsxy1.0.66 through 1.0.91 (22 versions, all malicious)Package fully malicious — remove and report; no fixed version exists✓npm RegistryUnattributed———
TL-2026-06212026-05-28mouse5212-super-formatter1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4unpublished from npm 2026-05-27✓npm registry (mouse5212-super-formatter maintainer)Unattributed———
TL-2026-06232026-05-29@vpmdhaj/devops-tools1.0.7267—✗@vpmdhajUnattributed———
TL-2026-06232026-05-29@vpmdhaj/elastic-helper1.0.7269—✗@vpmdhajUnattributed———
TL-2026-06232026-05-29@vpmdhaj/opensearch-setup1.0.7267—✗@vpmdhajUnattributed———
TL-2026-06232026-05-29@vpmdhaj/search-setup1.0.7268—✗@vpmdhajUnattributed———
TL-2026-06232026-05-29app-config-utility1.0.9300—✗—Unattributed———
TL-2026-06232026-05-29elastic-opensearch-helper1.0.9108—✗—Unattributed———
TL-2026-06232026-05-29env-config-manager2.1.9201—✗—Unattributed———
TL-2026-06232026-05-29opensearch-config-utility1.0.9106—✗—Unattributed———
TL-2026-06232026-05-29opensearch-security-scanner1.0.10—✗—Unattributed———
TL-2026-06232026-05-29opensearch-setup1.0.9103—✗—Unattributed———
TL-2026-06232026-05-29opensearch-setup-tool1.0.9108—✗—Unattributed———
TL-2026-06232026-05-29search-cluster-setup1.0.9104—✗—Unattributed———
TL-2026-06232026-05-29search-engine-setup1.0.9108—✗—Unattributed———
TL-2026-06232026-05-29vpmdhaj-opensearch-setup1.0.9102—✗—Unattributed———
TL-2026-06332026-05-29@capibar.chat/ui-kit——✗@capibar.chatUnattributed———
TL-2026-06332026-05-29@cloudplatform-single-spa/logaas——✗@cloudplatform-single-spaUnattributed———
TL-2026-06332026-05-29@sber-ecom-core/sberpay-widget——✗@sber-ecom-coreUnattributed———
TL-2026-06332026-05-29@wb-track/shared-front——✗@wb-trackUnattributed———
TL-2026-06412026-06-01codexui-android0.1.82, >=0.1.82 (malicious dist-cli build)clean GitHub source friuns2/codex-mobile (no malicious code)✓friuns2 (npm)Unattributed———
TL-2026-06432026-06-01@redhat-cloud-services/chrome2.3.1—✗@redhat-cloud-servicesTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-06432026-06-01@redhat-cloud-services/frontend-components7.7.2—✗@redhat-cloud-servicesTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-06432026-06-01@redhat-cloud-services/host-inventory-client5.0.3—✗@redhat-cloud-servicesTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-06432026-06-01@redhat-cloud-services/rbac-client9.0.3—✗@redhat-cloud-servicesTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-07262026-06-09buffer-util-extend——✗—Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07262026-06-09buffer-utilities1.0.0—✗—Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07262026-06-09chai-as-patch——✗—Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07262026-06-09chai-beta——✗—Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07262026-06-09express-denv——✗—Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07262026-06-09jwt-path——✗—Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07262026-06-09midcore——✗—Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07262026-06-09midcorp——✗—Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07262026-06-09node-background-invoker-v21.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6—✗—Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07262026-06-09react-next-dom——✗—Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07262026-06-09webpack-patch——✗—Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07332026-06-09@asyncapi/specs——✓@asyncapiShai-Hulud operatorsUnknown (cybercrime)Financial (credential/token theft worm)4
TL-2026-07332026-06-09@ctrl/tinycolor——✓@ctrlShai-Hulud operatorsUnknown (cybercrime)Financial (credential/token theft worm)4
TL-2026-07332026-06-09@postman/tunnel-agent——✓@postmanShai-Hulud operatorsUnknown (cybercrime)Financial (credential/token theft worm)4
TL-2026-07822026-06-12atomic-lockfile1.4.2Package removed; do not install✓npm RegistryUnattributed———
TL-2026-07822026-06-12js-digestall publishedPackage removed; do not install✓npm / bun RegistryUnattributed———
TL-2026-07882026-06-14atomic-lockfile1.4.2—✗—Unattributed———
TL-2026-07882026-06-14js-digest——✗—Unattributed———
TL-2026-08132026-06-15bjs-lint-builders——✗—Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-08132026-06-15nextjs-https-supertest——✗—Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-08132026-06-15nicegui0.1.4—✗—Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-08132026-06-15node-env-resolve——✗—Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-08132026-06-15period-newline0.1.0—✗—Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-08132026-06-15redeem-onchain-sdk1.0.7—✗—Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-08132026-06-15sleek-pretty——✗—Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-08132026-06-15vite-meta-plugin——✗—Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-08292026-06-16pipelinesany host installing the package—✗Developer / CI-CD environmentsShai-Hulud operatorsUnknown (cybercrime)Financial (credential/token theft worm)4
TL-2026-08292026-06-16shai_hulululud1.0.48596—✗npm (OpenJS / npm Registry)Shai-Hulud operatorsUnknown (cybercrime)Financial (credential/token theft worm)4
TL-2026-08342026-06-17@mastra/core1.42.1 (and all @mastra/core versions published 2026-06-17 without SLSA provenance), 1.42.1clean versions republished with valid provenance after 2026-06-17✓MastraLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-08342026-06-17@mastra/memory1.20.4post-incident clean republish✓MastraLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-08342026-06-17@mastra/schema-compat1.2.12post-incident clean republish✓MastraLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-08342026-06-17@mastra/server2.1.1post-incident clean republish✓MastraLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-08342026-06-17easy-day-js1.11.22 (weaponized), 1.11.21 (clean decoy, attacker-controlled), 1.11.21, 1.11.22remove entirely; not a legitimate package✓easy-day-js (typosquat, attacker-controlled)Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-08342026-06-17mastra1.13.1post-incident clean republish✓MastraLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-08362026-06-17@mastra/core——✗@mastraUnattributed———
TL-2026-08362026-06-17easy-day-js1.11.21, 1.11.22—✗—Unattributed———
TL-2026-08452026-06-17autoadv1.0.0—✗—Unattributed———
TL-2026-08452026-06-17node-dlls1.0.0—✗—Unattributed———
TL-2026-08452026-06-17ro.dll1.0.0—✗—Unattributed———
TL-2026-08452026-06-17rolimons-api1.1.0, 1.1.2—✗—Unattributed———
TL-2026-08982026-06-22easy-day-js1.11.22 (weaponized), 1.11.21 (clean decoy bait), 1.11.21, 1.11.22—✗npm (transitive dependency)APT38North Korea (DPRK)Financial theft9
TL-2026-09102026-06-23aes-decode-runner-pro——✗—Unattributed———
TL-2026-09102026-06-23postcss-minify-selector——✗—Unattributed———
TL-2026-09102026-06-23postcss-minify-selector-parser——✗—Unattributed———
TL-2026-09772026-06-17@mastra/coreAll versions republished 2026-06-17 during 27-minute compromise windowVersions released after Mastra maintainers revoked compromised package versions✓MastraLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-09772026-06-17easy-day-jsAll versions of the malicious easy-day-js packagePackage removed from registry; all versions yanked✓NPM RegistryLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-09872026-06-28fetch-page-assets1.2.9—✗npm (JavaScript Package Registry)Unattributed———
TL-2026-09872026-06-28html-to-gutenberg4.2.11—✗npm (JavaScript Package Registry)Unattributed———
TL-2026-10082026-06-30python-wolfssl——✗—Unattributed———
TL-2026-10302026-07-01fetch-page-assets——✗—Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-10302026-07-01html-to-gutenberg——✗—Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-10302026-07-01quirky-tokenall published versions (XRAY-1003392)package removed from npm registry✓npmLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-10302026-07-01react-icon-svgsall published versions (XRAY-1011624)package removed from npm registry✓npmLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-10302026-07-01rollup-packages-polyfill-coreall published versions (XRAY-1008625)package removed from npm registry✓npmLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-10302026-07-01rollup-plugin-polyfill-connectall published versions (XRAY-973019)package removed from npm registry✓npmLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-10302026-07-01rollup-runtime-polyfill-coreall published versions (XRAY-1008531)package removed from npm registry✓npmLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-10302026-07-01swift-parse-streamall published versions (XRAY-1005725)package removed from npm registry✓npmLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-10552026-07-01tailwind-animationbasedall published versionsnot confirmed✓npmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-10552026-07-01tailwind-autoanimation2.3.6removed from registry✓npmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-10552026-07-01tailwind-mainanimation2.3.30.0.1 security placeholder✓npmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-10552026-07-01tailwindcss-animate-style1.2.5not confirmed✓npmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-10552026-07-01tailwindcss-style-animate1.1.6removed from registry✓npmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-10552026-07-01tailwindcss-style-modify0.8.3not confirmed✓npmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-10552026-07-01tailwindcss-typography-style0.8.2not confirmed✓npmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-11202026-07-01tailwind-autoanimation——✗—Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-11202026-07-01tailwind-mainanimation——✗—Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-11202026-07-01tailwindcss-style-animate——✗—Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-11432026-06-21@aifabrix/miso-clientmalicious versionsN/A✓npmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-11432026-06-21@iflow-mcp/watercrawl-watercrawl-mcpmalicious versionsN/A✓npmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-11432026-06-21@usebioerhold8733/s-format4 incrementally-staged malicious versions published within a 48-hour windowN/A✓npmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-11432026-06-21tailwind-autoanimationall published malicious versions injecting payload into src/index.jsN/A✓npmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-11432026-06-21tailwind-mainanimationall published malicious versionsremoved by npm✓npmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-11432026-06-21tailwindcss-style-animate1.1.6 and re-published malicious versionspackage removed/scrubbed from registry✓npmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-11492026-07-08@injectivelabs/sdk-ts1.20.211.20.23✓Injective LabsUnattributed———
TL-2026-11532026-07-09@injectivelabs/exceptions1.20.211.20.23✓InjectiveLabsUnattributed———
TL-2026-11532026-07-09@injectivelabs/networks1.20.211.20.23✓InjectiveLabsUnattributed———
TL-2026-11532026-07-09@injectivelabs/sdk-ts1.20.211.20.23✓InjectiveLabsUnattributed———
TL-2026-11532026-07-09@injectivelabs/ts-types1.20.211.20.23✓InjectiveLabsUnattributed———
TL-2026-11532026-07-09@injectivelabs/utils1.20.211.20.23✓InjectiveLabsUnattributed———
TL-2026-11532026-07-09@injectivelabs/wallet-base1.20.211.20.23✓InjectiveLabsUnattributed———
TL-2026-11532026-07-09@injectivelabs/wallet-core1.20.211.20.23✓InjectiveLabsUnattributed———
TL-2026-11532026-07-09@injectivelabs/wallet-cosmos1.20.211.20.23✓InjectiveLabsUnattributed———
TL-2026-11532026-07-09@injectivelabs/wallet-cosmos-strategy1.20.211.20.23✓InjectiveLabsUnattributed———
TL-2026-11532026-07-09@injectivelabs/wallet-cosmostation1.20.211.20.23✓InjectiveLabsUnattributed———
TL-2026-11532026-07-09@injectivelabs/wallet-evm1.20.211.20.23✓InjectiveLabsUnattributed———
TL-2026-11532026-07-09@injectivelabs/wallet-ledger1.20.211.20.23✓InjectiveLabsUnattributed———
TL-2026-11532026-07-09@injectivelabs/wallet-magic1.20.211.20.23✓InjectiveLabsUnattributed———
TL-2026-11532026-07-09@injectivelabs/wallet-private-key1.20.211.20.23✓InjectiveLabsUnattributed———
TL-2026-11532026-07-09@injectivelabs/wallet-strategy1.20.211.20.23✓InjectiveLabsUnattributed———
TL-2026-11532026-07-09@injectivelabs/wallet-trezor1.20.211.20.23✓InjectiveLabsUnattributed———
TL-2026-11532026-07-09@injectivelabs/wallet-turnkey1.20.211.20.23✓InjectiveLabsUnattributed———
TL-2026-11532026-07-09@injectivelabs/wallet-wallet-connect1.20.211.20.23✓InjectiveLabsUnattributed———
TL-2026-11642026-07-10jscodeshift——✗—Unattributed———
TL-2026-11642026-07-10react-codemod——✗—Unattributed———
TL-2026-11642026-07-10react-codeshift——✗—Unattributed———
TL-2026-12152026-07-11safe-validate1.0.4—✗npm (deepthought26 publisher account)Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-12152026-07-11tailwind-color-shades1.0.2—✗npm (deepthought26 publisher account)Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-12332026-07-11jscrambler8.14.0, 8.13.08.13.0 (last known-clean; roll back pending official remediation)✓JscramblerUnattributed———
TL-2026-12342026-06-04@vapi-ai/server-sdk0.11.1, 0.11.2, 1.2.1, 1.2.2removed/unpublished versions post-2026-06-04✓npm (open source)TeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-12342026-06-04ai-sdk-ollama0.13.1, 1.1.1, 2.2.1, 3.8.5removed/unpublished versions post-2026-06-04✓npm (open source)TeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-12342026-06-04eslint-plugin-awaitly——✗—TeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-12342026-06-04executable-stories-cypress——✗—TeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-12342026-06-04node-env-resolver-aws——✗—TeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-12342026-06-04wrangler-deploy——✗—TeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-12382026-07-11jscrambler8.14.08.15.0, 8.13.0 (revert)✓jscramblerUnattributed———
TL-2026-12422026-06-26hexo-deployer-wrangler1.0.4n/a - malicious release✓llxlr (npm account)Unattributed———
TL-2026-12422026-06-26hexo-shoka-swiper0.1.10n/a - malicious release✓llxlr (npm account)Unattributed———
TL-2026-12422026-06-26leo-auth4.0.6revert to last known-clean version prior to 2026-06-24✓LeoPlatform/RStreamsUnattributed———
TL-2026-12422026-06-26leo-aws2.0.4pre-2026-06-24 release✓LeoPlatform/RStreamsUnattributed———
TL-2026-12422026-06-26leo-cache1.0.2pre-2026-06-24 release✓LeoPlatform/RStreamsUnattributed———
TL-2026-12422026-06-26leo-cdk-lib0.0.2pre-2026-06-24 release✓LeoPlatform/RStreamsUnattributed———
TL-2026-12422026-06-26leo-cli3.0.3pre-2026-06-24 release✓LeoPlatform/RStreamsUnattributed———
TL-2026-12422026-06-26leo-config1.1.1pre-2026-06-24 release✓LeoPlatform/RStreamsUnattributed———
TL-2026-12422026-06-26leo-connector-elasticsearch2.0.6pre-2026-06-24 release✓LeoPlatform/RStreamsUnattributed———
TL-2026-12422026-06-26leo-connector-mongo3.0.8pre-2026-06-24 release✓LeoPlatform/RStreamsUnattributed———
TL-2026-12422026-06-26leo-connector-mysql3.0.3pre-2026-06-24 release✓LeoPlatform/RStreamsUnattributed———
TL-2026-12422026-06-26leo-connector-oracle2.0.1pre-2026-06-24 release✓LeoPlatform/RStreamsUnattributed———
TL-2026-12422026-06-26leo-connector-redshift3.0.6pre-2026-06-24 release✓LeoPlatform/RStreamsUnattributed———
TL-2026-12422026-06-26leo-cron2.0.2pre-2026-06-24 release✓LeoPlatform/RStreamsUnattributed———
TL-2026-12422026-06-26leo-logger1.0.8pre-2026-06-24 release✓LeoPlatform/RStreamsUnattributed———
TL-2026-12422026-06-26leo-sdk6.0.19pre-2026-06-24 release✓LeoPlatform/RStreamsUnattributed———
TL-2026-12422026-06-26leo-streams2.0.1pre-2026-06-24 release✓LeoPlatform/RStreamsUnattributed———
TL-2026-12422026-06-26prism-silq1.0.1n/a - malicious release✓llxlr (npm account)Unattributed———
TL-2026-12422026-06-26rstreams-metrics2.0.2pre-2026-06-24 release✓LeoPlatform/RStreamsUnattributed———
TL-2026-12422026-06-26rstreams-shard-util1.0.1pre-2026-06-24 release✓LeoPlatform/RStreamsUnattributed———
TL-2026-12422026-06-26serverless-convention2.0.4pre-2026-06-24 release✓LeoPlatform/RStreamsUnattributed———
TL-2026-12422026-06-26serverless-leo3.0.14pre-2026-06-24 release✓LeoPlatform/RStreamsUnattributed———
TL-2026-12422026-06-26solo-nav1.0.1n/a - malicious release✓llxlr (npm account)Unattributed———
TL-2026-12422026-06-26verana-blockchainv0.10.1-dev.20revert to clean prior commit/tag✓Verana LabsUnattributed———
TL-2026-12932026-07-14@asyncapi/generator3.3.1—✗AsyncAPI InitiativeMiasma operatorsUnknown (cybercrime)Financial (self-propagating worm)3
TL-2026-12932026-07-14@asyncapi/generator-components0.7.1—✗AsyncAPI InitiativeMiasma operatorsUnknown (cybercrime)Financial (self-propagating worm)3
TL-2026-12932026-07-14@asyncapi/generator-helpers1.1.1—✗AsyncAPI InitiativeMiasma operatorsUnknown (cybercrime)Financial (self-propagating worm)3
TL-2026-12932026-07-14@vapi-ai/server-sdk0.11.1, 0.11.2, 1.2.1, 1.2.2—✗VapiMiasma operatorsUnknown (cybercrime)Financial (self-propagating worm)3
TL-2026-12962026-07-14changiairportpromax——✗—Unattributed———
TL-2026-12962026-07-14charlie-kirk——✗—Unattributed———
TL-2026-12962026-07-14ilovefemboys——✗—Unattributed———
TL-2026-12962026-07-14miguelphonk——✗—Unattributed———
TL-2026-12962026-07-14ratelimitsucks——✗—Unattributed———
TL-2026-12992026-07-14@asyncapi/generator3.3.1unpublished/removed by npm and maintainers post-disclosure✓AsyncAPI InitiativeUnattributed———
TL-2026-12992026-07-14@asyncapi/generator-components0.7.1unpublished/removed by npm and maintainers post-disclosure✓AsyncAPI InitiativeUnattributed———
TL-2026-12992026-07-14@asyncapi/generator-helpers1.1.1unpublished/removed by npm and maintainers post-disclosure✓AsyncAPI InitiativeUnattributed———
TL-2026-12992026-07-14@asyncapi/specs6.11.2, 6.11.2-alpha.1unpublished/removed by npm and maintainers post-disclosure✓AsyncAPI InitiativeUnattributed———
TL-2026-13202026-07-14@asyncapi/generator3.3.13.3.0 (downgrade/pin)✓AsyncAPI InitiativeUnattributed———
TL-2026-13202026-07-14@asyncapi/generator-components0.7.10.7.0 (downgrade/pin)✓AsyncAPI InitiativeUnattributed———
TL-2026-13202026-07-14@asyncapi/generator-helpers1.1.11.1.0 (downgrade/pin)✓AsyncAPI InitiativeUnattributed———
TL-2026-13202026-07-14@asyncapi/specs6.11.2, 6.11.2-alpha.16.11.1 (downgrade/pin)✓AsyncAPI InitiativeUnattributed———
TL-2026-13602026-07-15@asyncapi/generator3.3.13.3.0 (rollback)✓AsyncAPI InitiativeUnattributed———
TL-2026-13602026-07-15@asyncapi/generator-components0.7.11.0.0✓AsyncAPI InitiativeUnattributed———
TL-2026-13602026-07-15@asyncapi/generator-helpers1.1.11.1.0 (rollback)✓AsyncAPI InitiativeUnattributed———
TL-2026-13602026-07-15@asyncapi/specs6.11.2, 6.11.2-alpha.16.11.1 (rollback)✓AsyncAPI InitiativeUnattributed———
TL-2026-13792026-07-15jscrambler8.14.0, 8.16.0, 8.17.0, 8.18.0, 8.20.08.22.0✓JscramblerUnattributed———
TL-2026-13812026-07-15@injectivelabs/exceptions1.20.211.20.23 or later✓Injective LabsUnattributed———
TL-2026-13812026-07-15@injectivelabs/networks1.20.211.20.23 or later✓Injective LabsUnattributed———
TL-2026-13812026-07-15@injectivelabs/sdk-ts1.20.211.20.23✓Injective LabsUnattributed———
TL-2026-13812026-07-15@injectivelabs/ts-types1.20.211.20.23 or later✓Injective LabsUnattributed———
TL-2026-13812026-07-15@injectivelabs/utils1.20.211.20.23 or later, or unpin from malicious version✓Injective LabsUnattributed———
TL-2026-13812026-07-15@injectivelabs/wallet-base1.20.211.20.23 or later✓Injective LabsUnattributed———
TL-2026-13812026-07-15@injectivelabs/wallet-core1.20.211.20.23 or later✓Injective LabsUnattributed———
TL-2026-13812026-07-15@injectivelabs/wallet-cosmos1.20.211.20.23 or later✓Injective LabsUnattributed———
TL-2026-13812026-07-15@injectivelabs/wallet-cosmos-strategy1.20.211.20.23 or later✓Injective LabsUnattributed———
TL-2026-13812026-07-15@injectivelabs/wallet-cosmostation1.20.211.20.23 or later✓Injective LabsUnattributed———
TL-2026-13812026-07-15@injectivelabs/wallet-evm1.20.211.20.23 or later✓Injective LabsUnattributed———
TL-2026-13812026-07-15@injectivelabs/wallet-ledger1.20.211.20.23 or later✓Injective LabsUnattributed———
TL-2026-13812026-07-15@injectivelabs/wallet-magic1.20.211.20.23 or later✓Injective LabsUnattributed———
TL-2026-13812026-07-15@injectivelabs/wallet-private-key1.20.211.20.23 or later✓Injective LabsUnattributed———
TL-2026-13812026-07-15@injectivelabs/wallet-strategy1.20.211.20.23 or later✓Injective LabsUnattributed———
TL-2026-13812026-07-15@injectivelabs/wallet-trezor1.20.211.20.23 or later✓Injective LabsUnattributed———
TL-2026-13812026-07-15@injectivelabs/wallet-turnkey1.20.211.20.23 or later✓Injective LabsUnattributed———
TL-2026-13812026-07-15@injectivelabs/wallet-wallet-connect1.20.211.20.23 or later✓Injective LabsUnattributed———
TL-2026-13872026-07-15@asyncapi/generator3.3.13.3.0✓AsyncAPI InitiativeUnattributed———
TL-2026-13872026-07-15@asyncapi/generator-components0.7.11.0.0✓AsyncAPI InitiativeUnattributed———
TL-2026-13872026-07-15@asyncapi/generator-helpers1.1.11.1.0✓AsyncAPI InitiativeUnattributed———
TL-2026-13872026-07-15@asyncapi/specs6.11.2-alpha.1, 6.11.26.11.1 or earlier✓AsyncAPI InitiativeUnattributed———

Sorted by threat ID (Threadlinqs TL number). Click any column header to re-sort; type to filter. Every TL number links to the full enriched threat record; every package links to its npm registry page; every attributed actor links to its actor profile. Vulnerable/fixed versions mirror each threat's // affected section. “Actor threats” is the number of threats attributed to that actor across the Threadlinqs corpus.

How to protect against npm supply chain attacks: a checklist

Prioritized for a security team working from the top down:

Frequently asked questions

What is an npm supply chain attack?

An npm supply chain attack compromises a trusted package in the npm registry — by stealing a maintainer's publish token, hijacking a dormant account, or poisoning the CI/CD pipeline that publishes it — so that every project installing the package also pulls attacker code. Because a single popular package can be a dependency of millions of projects, one compromise cascades across the ecosystem.

How many npm packages were compromised in 2026?

Between February 1 and July 15, 2026, Threadlinqs Intelligence documented 78 distinct npm supply chain attacks involving 218 unique malicious packages across 308 documented package records. The full, sortable list — with vulnerable and fixed versions and the attributed threat actor — is in the master table on this page.

What is the Shai-Hulud npm worm?

Shai-Hulud is a family of self-replicating npm worms — including Mini Shai-Hulud, Miasma, Hades, and the compiled-Rust IronWorm — that harvest cloud and CI credentials at install time and then auto-republish through the maintainer accounts they just stole from. It is the first true worm behavior in the npm ecosystem, turning one compromise into self-propagating malware. Threadlinqs links the lineage to a crew tracked as TeamPCP, present in 40 of the 78 documented attacks.

Who is behind the 2026 npm supply chain attacks?

Attribution splits two ways. North Korea (DPRK) accounts for 23 of the 78 attacks (56% of those with a named actor), spread across the UNC1069/Sapphire Sleet, APT38, Lazarus Group, Contagious Interview, WageMole, and PolinRider clusters, motivated by cryptocurrency and credential theft. The other pole is financially motivated crimeware led by TeamPCP and its self-replicating worm family.

What is a binding.gyp "Phantom Gyp" attack?

Phantom Gyp is an install-time execution technique that avoids the obvious postinstall hook. An attacker drops a small binding.gyp file into a pure-JavaScript package; npm then invokes node-gyp during install, and node-gyp's command-substitution syntax executes attacker code without any lifecycle script being declared. The Miasma worm used a 157-byte binding.gyp to trojanize dozens of packages across hundreds of versions.

What is slopsquatting?

Slopsquatting (also called HalluSquatting) is a name-based attack that weaponizes AI: attackers pre-register the plausible-but-nonexistent package names that large language models hallucinate, so that when an AI coding assistant confidently suggests one of those names, the developer installs attacker-controlled code. It is typosquatting adapted to the era of AI-generated dependency suggestions.

How do I protect against npm supply chain attacks?

Enforce package provenance (npm audit signatures and SLSA), set --ignore-scripts by default in CI, pin exact versions with integrity hashes in committed lockfiles, scope publish tokens narrowly and prefer short-lived OIDC over legacy tokens, revoke dormant maintainer access, and adopt the npm 12 defaults that disable lifecycle scripts, node-gyp, Git dependencies, and remote tarballs. The remediation checklist on this page prioritizes these for a security team.

Track this in real time

Threadlinqs Intelligence tracks npm supply chain compromises as they happen — every package, version, IOC, detection rule, and threat actor, enriched and cross-linked. This article is a snapshot; the platform is live and updated nightly.

Start a free 7-day trial of Purple — the full detection library, real-time IOC enrichment, MCP access, and the correlation engine. Create an account to begin; no card required to start the trial.

[ start_free_7_day_trial ]

Sources and further reading

Published by the Threadlinqs Team under our editorial standards and corrections policy.