78 THREATS HIGH 2026-07-16 Comprehensive Report

npm Supply Chain Attacks 2026: The Definitive Record of Every Documented Compromise

Threadlinqs Team 19 min read
npm supply chain attacksshai-huludslopsquattingbinding.gypdprkteampcpnpm wormaxiosmastraasyncapisoftware supply chain

Between February 1 and July 15, 2026, Threadlinqs Intelligence documented 78 npm supply chain attacks spanning 218 malicious npm packages — self-replicating worms, CI/CD pipeline hijacks, AI-agent credential theft, and industrialized DPRK campaigns. Two throughlines dominate the window: a single crimeware crew, TeamPCP, linked to 40 of the 78 threats through the Shai-Hulud worm lineage, and North Korea, behind 23. This is the full reference: every wave, every technique, and every documented package, each mapped back to its threat record and attributed actor.

npm supply chain attacks by the numbers

78
npm supply-chain threats
218
compromised packages
23
DPRK-attributed (29%)
12
threat actors tracked
702
detection rules
Threats per month, by attribution
DPRKFinancially motivatedUnattributed
01020Feb: 1 unattributedFeb: 1 DPRK2Mar: 3 financially motivatedMar: 4 DPRK7Apr: 1 unattributedApr: 5 financially motivatedApr: 7 DPRK13May: 9 unattributedMay: 4 financially motivatedMay: 1 DPRK14Jun: 12 unattributedJun: 5 financially motivatedJun: 6 DPRK23Jul: 14 unattributedJul: 1 financially motivatedJul: 4 DPRK19FebMarAprMayJunJul
Nation-state activity leads early; unattributed crimeware and worms dominate the later months. July is partial (through the 15th).
Cumulative compromised packages
050100150200Feb: 0 cumulative packages0Mar: 39 cumulative packages39Apr: 56 cumulative packages56May: 102 cumulative packages102Jun: 180 cumulative packages180Jul: 218 cumulative packages218FebMarAprMayJunJul
Distinct npm packages with at least one documented malicious version, accumulating to 218 across the window.

Timeline: the major npm supply chain attacks of 2026

DateWaveThreatsWhat happened
Mar 2026PolinRider VS Code auto-run + blockchain dead-dropsTL-2026-0437DPRK implants spread across 1,951 GitHub repos via Tailwind/PostCSS typosquats and weaponized .vscode/tasks.json, resolving C2 from TRON/Aptos/BSC blockchains.
2026-03-11prt-scan GitHub Actions pwn-request campaignTL-2026-0318One actor with six disposable accounts opened malicious PRs against 500+ repos to exploit pull_request_target and exfiltrate CI/CD secrets in public logs (ran through Apr 3).
Apr 2026Axios compromise by UNC1069 / Sapphire SleetTL-2026-0305, TL-2026-0311, TL-2026-0397, TL-2026-0351A stolen legacy token honored over OIDC published backdoored axios via phantom dependency plain-crypto-js (~600K downloads in 3h); reached OpenAI's macOS signing pipeline, forcing cert rotation. CISA alert 04-20.
Apr 2026TeamPCP cascading Bitwarden/Checkmarx breachTL-2026-0425, TL-2026-0429Reused credentials from the Checkmarx breach poisoned checkmarx/ast-github-action to publish trojanized @bitwarden/cli, harvesting live vault exports and AI-tool configs. CISA AA26-115A.
Apr 2026Mini Shai-Hulud worm: SAP, Intercom, TanStack, @antvTL-2026-0439, TL-2026-0446, TL-2026-0499, TL-2026-0530, TL-2026-0547TeamPCP worm hit SAP CAP, intercom-client, @tanstack/react-router (~12M wk dl) and 200+ @antv packages using Bun-runtime execution, orphan-commit staging and OIDC token theft.
May 2026node-ipc backdoor + Megalodon mass-repo wormTL-2026-0518, TL-2026-0556, TL-2026-0557node-ipc backdoor (require-triggered, DNS-TXT exfil); Megalodon pushed workflow-injection commits to 5,561 GitHub repos in 6 hours, bleeding into npm via @tiledesk/tiledesk-server.
May 2026Cross-ecosystem stealers + cloud-secret typosquatsTL-2026-0576, TL-2026-0623, TL-2026-0633TrapDoor coordinated 34 packages across npm/PyPI/crates.io with zero-width AI-assistant injection; Microsoft flagged typosquat and dependency-confusion packages sweeping AWS/Vault/CI secrets.
May 2026AI becomes a target: Claude sandbox + Codex/MCPTL-2026-0621, TL-2026-0641, TL-2026-0712AI-generated "Malware-Slop" exfiltrated Claude's /mnt/user-data sandbox; codexui-android stole Codex OAuth tokens; a Mitiga PoC hijacked Claude Code MCP traffic for OAuth theft.
Jun 2026Miasma resurgence: RedHat, Microsoft repos, Phantom GypTL-2026-0643, TL-2026-0733, TL-2026-1234, TL-2026-0963, TL-2026-1293TeamPCP's Miasma worm poisoned @redhat-cloud-services and 73 Microsoft repos, introduced the binding.gyp "Phantom Gyp" vector (57 pkgs/286 versions) and abused the npm bypass_2fa API.
2026-06-17Mastra AI-framework mass-republishTL-2026-0898, TL-2026-0836, TL-2026-0977Sapphire Sleet hijacked the dormant ehindero account and republished 140+ @mastra packages (@mastra/core ~918K wk dl) in an ~88-minute burst, injecting the easy-day-js typosquat dependency.
Jun 2026Injective SDK wallet backdoor + Atomic Arch AUR pivotTL-2026-1153, TL-2026-1149, TL-2026-0788, TL-2026-097918 @injectivelabs packages backdoored to steal BIP-39 mnemonics via fake telemetry and HTTP-header exfil; Atomic Arch hijacked 400+ AUR packages to pull malicious npm packages with an eBPF rootkit.
Jun–Jul 2026PolinRider cross-ecosystem expansionTL-2026-1055, TL-2026-1120, TL-2026-1143, TL-2026-1215DPRK PolinRider scaled to 108 malicious packages/extensions (162 artifacts) across npm, Packagist, Go and the Chrome Web Store, with blockchain dead-drop C2 and build-config injection persistence.
Jul 2026AsyncAPI pwn-request → SLSA-signed MiasmaTL-2026-1360, TL-2026-1299, TL-2026-1320, TL-2026-1387An unpatched pull_request_target flaw stole the asyncapi-bot PAT; the project's own OIDC trusted-publishing shipped five malicious @asyncapi versions (~2.9M wk dl) with valid provenance, delivering Miasma at import time.
2026-07-11jscrambler / IronWorm security-vendor compromiseTL-2026-1379, TL-2026-1233, TL-2026-1238A stolen credential published five malicious jscrambler versions (8.14.0–8.20.0) dropping IronWorm, a Rust cross-platform stealer in the Shai-Hulud lineage; flagged in 6 minutes yet republished over 3 hours.
Jul 2026Ecosystem response + AI-native researchTL-2026-1163, TL-2026-1164npm 12 disabled lifecycle scripts, node-gyp, Git deps and remote tarballs by default (opt-in allowlist); researchers demonstrated HalluSquatting, pre-registering LLM-hallucinated names that nine AI coding assistants fetch.

How npm supply chain attacks changed in 2026: the novel techniques

The window's defining shift is that npm stopped being a place where attackers drop a single poisoned package and wait. It became a medium for self-propagating malware, a lever on the pipelines that publish, and a channel to reach AI agents. Eight technique families account for nearly everything documented.

Self-replicating npm worms — the Shai-Hulud lineage

For most of npm's history a compromise was a discrete event: one package, one bad version, one takedown. That model broke down with the Shai-Hulud worm family — the original Shai-Hulud first appeared in late 2025, and Mini Shai-Hulud, Miasma, Hades, and the compiled IronWorm escalated it sharply across this window — worms that harvest cloud and CI credentials at install time and then auto-republish through the very maintainers they just robbed. Socket and StepSecurity tracked the worm family to a crew tracked as TeamPCP, which Threadlinqs links to 40 of the 78 threats in the window; the Shai-Hulud and Miasma generations are carried as distinct operator labels within that lineage rather than as confirmed TeamPCP aliases.

The novelty is closed-loop propagation. Each generation kept the harvest-and-republish core while iterating tradecraft: Bun-runtime execution to sidestep Node tooling, orphan-commit payload staging so the malicious code never appears in the visible Git history, and TruffleHog secret sweeps across the compromised host. Miasma trojanized 57 npm packages across 286+ versions using a 157-byte binding.gyp "Phantom Gyp" that runs a 4–5MB ROT-N-obfuscated index.js during install, harvests AWS/GCP/Azure/Vault/Kubernetes/GitHub-Actions credentials, then propagates across CI/CD (TL-2026-1234). By July the lineage had crossed into compiled Rust with IronWorm (TL-2026-1379), hardening the payload against JavaScript-level scanners entirely.

Install-time and import-time execution without a visible install script

Attackers systematically abandoned the obvious postinstall hook — the first thing any scanner checks — for triggers that evade install-script analysis. Phantom Gyp is the standout: drop a binding.gyp into a pure-JS package and npm invokes node-gyp, whose command-substitution syntax executes code with no lifecycle script declared at all. Others moved execution into module require()/import (with sideEffects arrays to defeat tree-shaking), into preinstall so theft fires before code even unpacks, or into a downloaded Bun runtime that never touches Node-level tooling.

node-ipc 9.1.6/9.2.3/12.0.1 (~822K weekly downloads) fired its credential stealer on module require() rather than any lifecycle script, exfiltrating cloud, SSH, Kubernetes, and Terraform secrets over DNS TXT queries (TL-2026-0518). This pressure was the direct cause of npm 12 flipping lifecycle scripts, node-gyp, Git dependencies, and remote tarballs to opt-in (TL-2026-1163).

CI/CD trusted publishing as the new blast radius

The highest-leverage attacks stopped stealing npm tokens and hijacked the pipelines that publish. The recurring primitive is the GitHub Actions "pwn-request": a pull_request_target workflow that checks out untrusted PR code while holding base-repo secrets. From there, operators read OIDC tokens out of runner memory (/proc/<pid>/mem) and publish through the project's own trusted-publisher workflow — so the poisoned tarball carries valid SLSA provenance.

The AsyncAPI compromise is the clean example: an unpatched pull_request_target flaw leaked the asyncapi-bot PAT, then npm OIDC trusted publishing shipped five malicious @asyncapi versions (~2.9M weekly downloads) with provenance attesting the workflow, not the malicious commit (TL-2026-1360, TL-2026-1299). Automated worms weaponized the same primitive at scale: Megalodon touched 5,561 repos in six hours (TL-2026-0556) and a poisoned codfish/semantic-release-action exposed 1,442 repos. The Axios compromise took a different route — a stolen legacy NPM_TOKEN published the backdoor, which then reached OpenAI's macOS signing pipeline through a floating ^1.14.0 version range in the signing CI (TL-2026-0351), forcing an Apple Developer ID certificate rotation.

AI as both target and weapon

2026 is where AI entered the supply chain from both directions at once. As a target, AI-agent credentials and configs became the prize: OpenAI Codex OAuth tokens, Claude Code MCP OAuth bearer tokens, the Claude sandbox filesystem, and whole frameworks (Mastra, @mistralai). A Mitiga PoC's postinstall hook rewrote mcpServers URLs in ~/.claude.json to route Claude Code's MCP traffic through an attacker mitmproxy, seeded directory-trust flags, and injected a SessionStart hook to steal persistent OAuth bearer tokens for Jira and GitHub over MCP (TL-2026-0712).

As a weapon, AI generated the malware ("slop" packages, language-aware payloads), pre-registered the plausible package names that LLMs hallucinate so coding agents fetch them — a technique now called slopsquatting or HalluSquatting — and manipulated the LLM reviewers themselves. The package shai_hulululud embedded a fake SYSTEM-OVERRIDE prompt-injection and token-flooding to blind LLM scanners (TL-2026-0829). Socket, which first flagged the package, detailed the same prompt-injection technique. It is defense being attacked at its own layer.

Maintainer-trust and account-takeover tradecraft

Rather than exploit code, attackers exploited the trust model around publishing. Documented techniques include a stolen legacy NPM_TOKEN being honored over OIDC Trusted Publishing (bypassing 2FA), dormant contributor access that was never revoked, expired recovery-domain re-registration, social-engineered maintainer handovers, and abuse of the npm bypass_2fa API.

Nearly universal was "phantom-dependency injection" paired with "clean-decoy pre-staging": leave the trusted package's own code untouched and hide the malice one hop away, in a freshly added dependency whose benign decoy version was published hours earlier to defeat novelty heuristics. Backdoored axios@1.14.1/0.30.4 were bit-for-bit identical to the clean releases except one package.json line adding phantom dependency plain-crypto-js@^4.2.1, whose clean 4.2.0 decoy had been staged roughly 18 hours earlier; the maintainer's stolen legacy token was honored over OIDC despite MFA (TL-2026-0305, TL-2026-0397).

Novel C2 and exfiltration channels

Operators fled takedown-prone domains for infrastructure that is immutable, decentralized, or indistinguishable from legitimate traffic. Blockchain dead-drops resolved C2 that cannot be seized: PolinRider's tailwind-color-shades/safe-validate loaders queried TRON and Aptos and decrypted an XOR payload from Binance Smart Chain burn-address transactions — "EtherHiding" — to resolve C2 with no static domain (TL-2026-1215). Legitimate services became payload hosts (Hugging Face, IPFS, GitHub Releases and the Contents API, jsonkeeper and rentry pastes).

Exfiltration hid where egress filters do not look. The @injectivelabs backdoor base64-encoded stolen BIP-39 mnemonics into the X-Request-Id HTTP header, shaped to resemble gRPC-Web traffic (TL-2026-1149). Others used DNS TXT queries, WebRTC P2P, and Cloudflare Worker proxies to survive egress filtering.

DPRK industrialization of developer-targeting campaigns

North Korea moved from bespoke drops to automated malware factories. The Contagious Interview, PolinRider, and WageMole clusters mass-produced malicious packages in escalating waves — 67, then 108-package/261-version runs, then ~200-package OtterCookie batches — delivered through fake-recruiter coding-assessment lures on LinkedIn, Fiverr, and Upwork, plus brandjacking, VS Code tasks.json folderOpen auto-run, malicious git pre-commit hooks, and backdoored IDE-marketplace extensions.

PolinRider published 108 malicious packages and extensions across 162 artifacts spanning npm, Packagist, 80+ Go modules, and the Chrome Web Store, appending obfuscated JS to build-config files (tailwind.config.js, next.config.mjs) and abusing .vscode/tasks.json runOn: folderOpen to auto-run BeaverTail/InvisibleFerret the moment a repo opened (TL-2026-1055, TL-2026-1143). DPRK accounts drove 23 of the 78 threats, and the crypto-theft subset (UNC1069 and PolinRider) went straight for wallet keys.

Typosquatting, dependency-confusion, and cross-ecosystem registry abuse

The classic name-based vectors persisted but grew more sophisticated: inflated version numbers to win dist-tag resolution, brandjacking via suffix or embedding rather than raw typos, dependency-confusion against real internal corporate namespaces, and coordination across npm, PyPI, crates.io, Go, and the AUR under one toolchain. Two newer twists stand out. The Atomic Arch campaign legitimately adopted 400+ (later 1,500+) orphaned AUR packages and modified their PKGBUILD hooks to run npm install atomic-lockfile@1.4.2, whose preinstall hook executes a bundled Rust ELF that steals credentials and installs an eBPF rootkit — a Linux distro repo bridged into npm (TL-2026-0788, TL-2026-0979). Separately, operators abused the npm registry itself as a free CDN, hosting adware and DDoS-botnet payloads in packages with no install hook at all.

Who is behind the npm supply chain attacks?

North Korea dominates. Of the 78 threats, 23 (29%) are DPRK-attributed; of the 41 with a named actor, 23 (56%) trace to DPRK clusters. The rest of the attributed set is financially motivated crimeware, and 37 threats carry no confident attribution at all.

Who is behind them
DPRK: 23 of 78 (29%)Financially motivated: 18 of 78 (23%)Unattributed: 37 of 78 (47%)78threats
DPRK — 23 (29%)Financially motivated — 18 (23%)Unattributed — 37 (47%)

The DPRK clusters overlap by design. Lazarus Group carries the most links (18 threats), reflecting its role as the umbrella under which the sub-clusters operate. Contagious Interview (11 threats) runs the fake-recruiter coding-assessment lures. WageMole (10) handles the IT-worker fraud angle. UNC1069 — the Sapphire Sleet cluster — and APT38 (9 each) drive the financially motivated theft, with UNC1069 behind the Axios and Mastra compromises. PolinRider (4) is the crypto-theft and cross-ecosystem specialist. The unifying motive is money — cryptocurrency wallet keys and developer credentials that convert to access — not espionage in the traditional sense.

The financially motivated crimeware side is defined by one crew. TeamPCP is the single biggest throughline in the entire dataset, linked to 40 threats via the self-replicating worm family. Where DPRK mass-produces discrete packages, TeamPCP built self-propagating malware — the difference between a factory and a contagion. The Shai-Hulud operators (4) and Miasma operators (3) are tracked as related-but-distinct labels for generations of the same lineage. ShinyHunters (15) surfaces around the data-theft and extortion tail, and TrapDoor and PhantomRaven (1 each) round out the cross-ecosystem crypto-stealer crews.

Most active actors, by documented threats
DPRK clusterFinancially motivated
TeamPCPTeamPCP: 4040Lazarus GroupLazarus Group: 1818ShinyHuntersShinyHunters: 1515Contagious InterviewContagious Interview: 1111WageMoleWageMole: 1010UNC1069UNC1069: 99APT38APT38: 99PolinRiderPolinRider: 44
Counts span the full Threadlinqs corpus, not only npm. TeamPCP’s worm lineage is the single largest throughline.

Attribution here is provisional. Worms muddy it further: once a self-propagating payload harvests one maintainer's token and republishes, the "actor" behind a given malicious version may be an automated loop rather than a human operator making a decision. Treat the named-actor column in the master list as an assessment, not a verdict.

How to detect and prevent npm supply chain attacks

The following detections are drawn from the Threadlinqs platform and map to the threats above. Trim the field names to your schema.

Mini Shai-Hulud fires its payload from a lifecycle hook spawning node/bun/python on a staged script — the earliest observable in the kill chain (TL-2026-0446):

sigmatitle: Mini Shai-Hulud npm/pip Preinstall Hook Spawns node-bun on setup.mjs or router_runtime.js
status: experimental
description: Detects npm/yarn/pnpm/pip lifecycle hooks invoking node, bun, or python on
  setup.mjs, router_runtime.js, or the Mini Shai-Hulud trojanized packages (intercom-client,
  @cap-js/*, mbt, lightning).
references:
    - https://socket.dev/blog/intercom-s-npm-package-compromised-in-supply-chain-attack
logsource:
    category: process_creation

The credential sweep that follows install — a node/bun process reading .npmrc, .aws/credentials, .kube/config, .vault-token, and terraform.tfstate within minutes of an install firing (TL-2026-0446):

kqllet credPaths = dynamic([".npmrc", ".yarnrc", "hosts.yml", ".docker/config.json",
    ".aws/credentials", ".kube/config", ".vault-token", ".env", ".envrc",
    "terraform.tfstate", ".gitconfig"]);
DeviceFileEvents
| where Timestamp > ago(24h)
| where ActionType in ("FileAccessed", "FileOpened", "FileRead")
| where InitiatingProcessFileName has_any ("node", "node.exe", "bun", "bun.exe",
    "python", "python3", "npm", "npm.cmd")
| where FileName has_any (credPaths)

Worm propagation is visible as a burst of patch-version publishes from a maintainer dormant for 30+ days, or GitHub repos created with the worm's signature description (TL-2026-0446):

kqllet poisonRepoPrefixes = dynamic(["ghola-melange-", "mentat-melange-", "powindah-sietch-"]);
let poisonDescription = "A Mini Shai-Hulud has Appeared";
GitHubAuditLog_CL
| where TimeGenerated > ago(24h)
| where action_s in ("repo.create", "repo.transfer", "public_repo.create")
| extend RepoName = tostring(repo_s), Description = tostring(description_s)
| where Description has poisonDescription
   or RepoName startswith_cs "ghola-melange-"

For the AI-agent surface, watch MCP config files in AI coding-assistant directories for injection (TL-2026-0147):

kqlDeviceFileEvents
| where Timestamp > ago(24h)
| where FolderPath has_any (".claude", ".cursor", ".continue", ".codeium", ".windsurf")
| where FileName in~ ("settings.json", "mcp.json", "config.json", "mcp_config.json")
| where ActionType in ("FileCreated", "FileModified")

And the exfil tail — Node fetching Pastebin raw URLs mid-install as a dead-drop C2 resolver (TL-2026-0152):

splindex=proxy sourcetype="bluecoat:proxysg:access:syslog" OR sourcetype="squid:access"
| search cs_host="pastebin.com" cs_uri_path="/raw/*"
| eval is_known_deaddrop=if(match(cs_uri_path, "(CJ5PrtNk|0ec7i68M|DjDCxcsT)"), 1, 0)
| stats count as paste_fetches, sum(is_known_deaddrop) as known_hits by src_ip, cs_User_Agent
| where paste_fetches >= 1

Beyond detection, the hygiene that would have blunted most of this window:

Every documented npm package: the master list

The table below is the full package-level record for the window — every documented malicious package and version, sorted by TL number, each row linking to its threat and enriched with the attributed actor and that actor's country and motive. Use it as a blocklist source and a triage reference; the "Actor" column is an assessment, not a confirmed verdict.

Largest namespace compromises
@emilgroup@emilgroup: 2828@injectivelabs@injectivelabs: 1818@antv@antv: 55@tanstack@tanstack: 44@redhat-cloud-services@redhat-cloud-services: 44@asyncapi@asyncapi: 44@mastra@mastra: 44
@emilgroup (CanisterWorm) and @injectivelabs (wallet-key backdoor) are the widest single-namespace hits in the window.
308 rows · 218 packages · 67 threats
TL #PublishedPackage VulnerableFixedPatchedVendor / namespace Threat actorCountryMotiveActor threats
TL-2026-02312026-03-15@aifabrix/miso-client4.7.2@aifabrixPhantomRavenUnknown (cybercrime)Financial (credential theft)1
TL-2026-02312026-03-15@iflow-mcp/watercrawl-watercrawl-mcp1.3.0-1.3.4@iflow-mcpPhantomRavenUnknown (cybercrime)Financial (credential theft)1
TL-2026-02592026-03-20@emilgroup/account-sdk1.41.1, 1.41.2emilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/account-sdk-nodepatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/accounting-sdk-nodepatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/api-documentationpatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/auth-sdkpatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/auth-sdk-nodepatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/billing-sdkpatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/billing-sdk-nodepatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/claim-sdkpatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/claim-sdk-nodepatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/customer-sdkpatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/customer-sdk-nodepatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/document-sdkpatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/document-sdk-nodepatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/gdv-sdkpatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/insurance-sdkpatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/insurance-sdk-nodepatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/notification-sdk-nodepatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/partner-portal-sdk-nodepatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/partner-sdk-nodepatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/payment-sdkpatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/payment-sdk-nodepatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/process-manager-sdk-nodepatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/public-api-sdkpatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/public-api-sdk-nodepatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/tenant-sdkpatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/tenant-sdk-nodepatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@emilgroup/translation-sdk-nodepatch .x.1, .x.2 versionsemilgroupTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02592026-03-20@teale.io/eslint-config1.8.9, 1.8.10teale.ioTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02792026-03-24ast-github-actionv2.3.28CheckmarxTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02792026-03-24kics-github-actionv1.1CheckmarxTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02792026-03-24setup-trivy0.2.0-0.2.6 (original)0.2.6 (recreated)Aqua SecurityTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-02792026-03-24trivy-action0.0.1-0.34.2 (76 tags)0.35.0Aqua SecurityTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-03002026-03-30axios1.14.1, 0.30.41.14.0, 0.30.3axiosUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03002026-03-30plain-crypto-js4.2.1nrwiseUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03012026-03-31@qqbrowser/openclaw-qbot0.0.130qqbrowserUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03012026-03-31@shadanai/openclaw2026.3.28-2, 2026.3.28-3, 2026.3.31-1, 2026.3.31-2shadanaiUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03012026-03-31axios1.14.1, 0.30.41.14.0, 0.30.3axiosUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03012026-03-31plain-crypto-js4.2.1nrwiseUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03032026-03-31@qqbrowser/openclaw-qbot0.0.130Package reported for removalnpmUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03032026-03-31@shadanai/openclaw2026.3.28-2, 2026.3.28-3, 2026.3.31-1, 2026.3.31-2Package reported for removalnpmUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03032026-03-31axios1.14.1, 0.30.4All other versions (malicious versions unpublished)axiosUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03032026-03-31plain-crypto-js4.2.1Package removed from npmnpmUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03052026-03-31@qqbrowser/openclaw-qbot0.0.130npmUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03052026-03-31@shadanai/openclaw2026.3.31-1, 2026.3.31-2npmUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03052026-03-31axios1.14.1, 0.30.41.14.2, 1.14.0, 0.30.3axiosUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03052026-03-31plain-crypto-js4.2.1npmUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03092026-04-01axios1.14.1, 0.30.41.14.0, 0.30.3axiosUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03092026-04-01plain-crypto-jsallremoved from npmunknownUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03112026-04-01@qqbrowser/openclaw-qbot0.0.130npmAPT38North Korea (DPRK)Financial theft9
TL-2026-03112026-04-01@shadanai/openclaw2026.3.28-2, 2026.3.28-3, 2026.3.31-1, 2026.3.31-2npmAPT38North Korea (DPRK)Financial theft9
TL-2026-03112026-04-01axios1.14.1, 0.30.41.14.2, 0.30.3axiosAPT38North Korea (DPRK)Financial theft9
TL-2026-03112026-04-01plain-crypto-js4.2.1npmAPT38North Korea (DPRK)Financial theft9
TL-2026-03142026-04-02axios1.14.1, 0.30.41.14.2, 0.30.5axiosUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03142026-04-02plain-crypto-js4.2.1npmUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03322026-04-07express-session-jsLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-03322026-04-07graphalgoLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-03322026-04-07react-plaid-sdkLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-03512026-04-11axios1.14.1, 0.30.41.14.0, 0.30.3axiosUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03512026-04-11plain-crypto-js4.2.1, 4.2.0Unknown (malicious)UNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03972026-04-20axios1.14.1, 0.30.41.14.0, 0.30.3AxiosUNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-03972026-04-20plain-crypto-js4.2.1, 4.2.00.0.1-security.0 (npm security-holder stub)nrwise (attacker-controlled)UNC1069North Korea (DPRK)Cryptocurrency theft9
TL-2026-04252026-04-27@bitwarden/cli2026.4.72026.4.8, 2026.4.6BitwardenTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04292026-04-27@bitwarden/cli2026.4.02026.4.1BitwardenTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04372026-04-29tailwind-animationbasedallnpm Inc. (registry)PolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-04372026-04-29tailwind-autoanimation2.3.6npm Inc. (registry)PolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-04372026-04-29tailwind-mainanimation2.3.3npm Inc. (registry)PolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-04372026-04-29tailwindcss-animate-styleallnpm Inc. (registry)PolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-04372026-04-29tailwindcss-style-animate1.1.6npm Inc. (registry)PolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-04372026-04-29tailwindcss-style-modify0.8.3npm Inc. (registry)PolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-04372026-04-29tailwindcss-typography-style0.8.2npm Inc. (registry)PolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-04392026-04-30@cap-js/db-service2.10.1SAP cap-jsTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04392026-04-30@cap-js/postgres2.2.2SAP cap-jsTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04392026-04-30@cap-js/sqlite2.2.2SAP cap-jsTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04392026-04-30mbt1.2.48TeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04462026-04-30@cap-js/db-service2.10.1post-2.10.1SAPTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04462026-04-30@cap-js/postgres2.2.2post-2.2.2SAPTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04462026-04-30@cap-js/sqlite2.2.2post-2.2.2SAPTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04462026-04-30intercom-client7.0.47.0.5+IntercomTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04462026-04-30lightning2.6.2, 2.6.32.6.1, 2.6.4+Lightning AITeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04462026-04-30mbt1.2.48TeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04992026-05-12@mistralai/mistralai2.2.2, 2.2.3, 2.2.4Mistral AITeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04992026-05-12@tanstack/react-router1.169.5, 1.169.8TanStackTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04992026-05-12guardrails-ai0.10.1Guardrails AITeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-04992026-05-12mistralai2.4.6Mistral AITeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05182026-05-15node-ipc9.1.6, 9.2.3, 12.0.1any clean release reverted post-incident; pin to <= 9.2.2 or >= 12.0.2 with verified integrity hashnode-ipc maintainers (npm)Unattributed
TL-2026-05282026-05-18@deadcode09284814/axios-util@deadcode09284814Unattributed
TL-2026-05282026-05-18axois-utilsUnattributed
TL-2026-05282026-05-18chalk-tempalteUnattributed
TL-2026-05282026-05-18color-style-utilsUnattributed
TL-2026-05302026-05-19@antv/component2.2.11@antvTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05302026-05-19@antv/g25.5.8@antvTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05302026-05-19@antv/g65.2.1@antvTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05302026-05-19@antv/mcp-server-chart0.10.10@antvTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05302026-05-19@antv/util3.4.11@antvTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05302026-05-19nrwl.angular-console18.95.018.94.x or post-incident >= 18.96.0NrwlTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05472026-05-21@tanstack/react-router1.169.5, 1.169.81.169.9+TanStackTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05472026-05-21@tanstack/router-core1.169.5, 1.169.81.169.9+TanStackTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05472026-05-21@tanstack/solid-router1.169.5, 1.169.81.169.9+TanStackTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05472026-05-21@tanstack/vue-router1.169.5, 1.169.81.169.9+TanStackTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-05562026-05-21@tiledesk/tiledesk-server2.18.6, 2.18.7, 2.18.8, 2.18.9, 2.18.10, 2.18.11, 2.18.12TiledeskUnattributed
TL-2026-05592026-05-22pinno-loggersall published versionsnpm registry (OpenJS / GitHub)Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-05592026-05-22pretty-logger-utilsall published versionsnpm registry (OpenJS / GitHub)Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-05592026-05-22terminal-logger-utilsall published versionsnpm registry (OpenJS / GitHub)Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-05592026-05-22ts-logger-packall published versionsnpm registry (OpenJS / GitHub)Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-05682026-05-22art-template4.13.3, 4.13.5, 4.13.6, 4.13.44.13.2 (last known clean release, 2018-11-13)aui (original) / daughtrymom + npmpacketmaintainmember7 (npm hijacker)Unattributed
TL-2026-05762026-05-24crates.io6 Sui/Move-themed cratescrates yankedRust FoundationTrapDoorUnknown (cybercrime)Financial (crypto wallet theft)1
TL-2026-06082026-05-27forge-jsx1.0.0 through 1.0.66 (66 versions, all malicious)Replaced by npm security placeholder on 2026-05-04npm RegistryUnattributed
TL-2026-06082026-05-27forge-jsxy1.0.66 through 1.0.91 (22 versions, all malicious)Package fully malicious — remove and report; no fixed version existsnpm RegistryUnattributed
TL-2026-06212026-05-28mouse5212-super-formatter1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4unpublished from npm 2026-05-27npm registry (mouse5212-super-formatter maintainer)Unattributed
TL-2026-06232026-05-29@vpmdhaj/devops-tools1.0.7267@vpmdhajUnattributed
TL-2026-06232026-05-29@vpmdhaj/elastic-helper1.0.7269@vpmdhajUnattributed
TL-2026-06232026-05-29@vpmdhaj/opensearch-setup1.0.7267@vpmdhajUnattributed
TL-2026-06232026-05-29@vpmdhaj/search-setup1.0.7268@vpmdhajUnattributed
TL-2026-06232026-05-29app-config-utility1.0.9300Unattributed
TL-2026-06232026-05-29elastic-opensearch-helper1.0.9108Unattributed
TL-2026-06232026-05-29env-config-manager2.1.9201Unattributed
TL-2026-06232026-05-29opensearch-config-utility1.0.9106Unattributed
TL-2026-06232026-05-29opensearch-security-scanner1.0.10Unattributed
TL-2026-06232026-05-29opensearch-setup1.0.9103Unattributed
TL-2026-06232026-05-29opensearch-setup-tool1.0.9108Unattributed
TL-2026-06232026-05-29search-cluster-setup1.0.9104Unattributed
TL-2026-06232026-05-29search-engine-setup1.0.9108Unattributed
TL-2026-06232026-05-29vpmdhaj-opensearch-setup1.0.9102Unattributed
TL-2026-06332026-05-29@capibar.chat/ui-kit@capibar.chatUnattributed
TL-2026-06332026-05-29@cloudplatform-single-spa/logaas@cloudplatform-single-spaUnattributed
TL-2026-06332026-05-29@sber-ecom-core/sberpay-widget@sber-ecom-coreUnattributed
TL-2026-06332026-05-29@wb-track/shared-front@wb-trackUnattributed
TL-2026-06412026-06-01codexui-android0.1.82, >=0.1.82 (malicious dist-cli build)clean GitHub source friuns2/codex-mobile (no malicious code)friuns2 (npm)Unattributed
TL-2026-06432026-06-01@redhat-cloud-services/chrome2.3.1@redhat-cloud-servicesTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-06432026-06-01@redhat-cloud-services/frontend-components7.7.2@redhat-cloud-servicesTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-06432026-06-01@redhat-cloud-services/host-inventory-client5.0.3@redhat-cloud-servicesTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-06432026-06-01@redhat-cloud-services/rbac-client9.0.3@redhat-cloud-servicesTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-07262026-06-09buffer-util-extendLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07262026-06-09buffer-utilities1.0.0Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07262026-06-09chai-as-patchLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07262026-06-09chai-betaLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07262026-06-09express-denvLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07262026-06-09jwt-pathLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07262026-06-09midcoreLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07262026-06-09midcorpLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07262026-06-09node-background-invoker-v21.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07262026-06-09react-next-domLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07262026-06-09webpack-patchLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-07332026-06-09@asyncapi/specs@asyncapiShai-Hulud operatorsUnknown (cybercrime)Financial (credential/token theft worm)4
TL-2026-07332026-06-09@ctrl/tinycolor@ctrlShai-Hulud operatorsUnknown (cybercrime)Financial (credential/token theft worm)4
TL-2026-07332026-06-09@postman/tunnel-agent@postmanShai-Hulud operatorsUnknown (cybercrime)Financial (credential/token theft worm)4
TL-2026-07822026-06-12atomic-lockfile1.4.2Package removed; do not installnpm RegistryUnattributed
TL-2026-07822026-06-12js-digestall publishedPackage removed; do not installnpm / bun RegistryUnattributed
TL-2026-07882026-06-14atomic-lockfile1.4.2Unattributed
TL-2026-07882026-06-14js-digestUnattributed
TL-2026-08132026-06-15bjs-lint-buildersContagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-08132026-06-15nextjs-https-supertestContagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-08132026-06-15nicegui0.1.4Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-08132026-06-15node-env-resolveContagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-08132026-06-15period-newline0.1.0Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-08132026-06-15redeem-onchain-sdk1.0.7Contagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-08132026-06-15sleek-prettyContagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-08132026-06-15vite-meta-pluginContagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-08292026-06-16pipelinesany host installing the packageDeveloper / CI-CD environmentsShai-Hulud operatorsUnknown (cybercrime)Financial (credential/token theft worm)4
TL-2026-08292026-06-16shai_hulululud1.0.48596npm (OpenJS / npm Registry)Shai-Hulud operatorsUnknown (cybercrime)Financial (credential/token theft worm)4
TL-2026-08342026-06-17@mastra/core1.42.1 (and all @mastra/core versions published 2026-06-17 without SLSA provenance), 1.42.1clean versions republished with valid provenance after 2026-06-17MastraLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-08342026-06-17@mastra/memory1.20.4post-incident clean republishMastraLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-08342026-06-17@mastra/schema-compat1.2.12post-incident clean republishMastraLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-08342026-06-17@mastra/server2.1.1post-incident clean republishMastraLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-08342026-06-17easy-day-js1.11.22 (weaponized), 1.11.21 (clean decoy, attacker-controlled), 1.11.21, 1.11.22remove entirely; not a legitimate packageeasy-day-js (typosquat, attacker-controlled)Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-08342026-06-17mastra1.13.1post-incident clean republishMastraLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-08362026-06-17@mastra/core@mastraUnattributed
TL-2026-08362026-06-17easy-day-js1.11.21, 1.11.22Unattributed
TL-2026-08452026-06-17autoadv1.0.0Unattributed
TL-2026-08452026-06-17node-dlls1.0.0Unattributed
TL-2026-08452026-06-17ro.dll1.0.0Unattributed
TL-2026-08452026-06-17rolimons-api1.1.0, 1.1.2Unattributed
TL-2026-08982026-06-22easy-day-js1.11.22 (weaponized), 1.11.21 (clean decoy bait), 1.11.21, 1.11.22npm (transitive dependency)APT38North Korea (DPRK)Financial theft9
TL-2026-09102026-06-23aes-decode-runner-proUnattributed
TL-2026-09102026-06-23postcss-minify-selectorUnattributed
TL-2026-09102026-06-23postcss-minify-selector-parserUnattributed
TL-2026-09772026-06-17@mastra/coreAll versions republished 2026-06-17 during 27-minute compromise windowVersions released after Mastra maintainers revoked compromised package versionsMastraLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-09772026-06-17easy-day-jsAll versions of the malicious easy-day-js packagePackage removed from registry; all versions yankedNPM RegistryLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-09872026-06-28fetch-page-assets1.2.9npm (JavaScript Package Registry)Unattributed
TL-2026-09872026-06-28html-to-gutenberg4.2.11npm (JavaScript Package Registry)Unattributed
TL-2026-10082026-06-30python-wolfsslUnattributed
TL-2026-10302026-07-01fetch-page-assetsLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-10302026-07-01html-to-gutenbergLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-10302026-07-01quirky-tokenall published versions (XRAY-1003392)package removed from npm registrynpmLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-10302026-07-01react-icon-svgsall published versions (XRAY-1011624)package removed from npm registrynpmLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-10302026-07-01rollup-packages-polyfill-coreall published versions (XRAY-1008625)package removed from npm registrynpmLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-10302026-07-01rollup-plugin-polyfill-connectall published versions (XRAY-973019)package removed from npm registrynpmLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-10302026-07-01rollup-runtime-polyfill-coreall published versions (XRAY-1008531)package removed from npm registrynpmLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-10302026-07-01swift-parse-streamall published versions (XRAY-1005725)package removed from npm registrynpmLazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-10552026-07-01tailwind-animationbasedall published versionsnot confirmednpmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-10552026-07-01tailwind-autoanimation2.3.6removed from registrynpmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-10552026-07-01tailwind-mainanimation2.3.30.0.1 security placeholdernpmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-10552026-07-01tailwindcss-animate-style1.2.5not confirmednpmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-10552026-07-01tailwindcss-style-animate1.1.6removed from registrynpmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-10552026-07-01tailwindcss-style-modify0.8.3not confirmednpmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-10552026-07-01tailwindcss-typography-style0.8.2not confirmednpmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-11202026-07-01tailwind-autoanimationContagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-11202026-07-01tailwind-mainanimationContagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-11202026-07-01tailwindcss-style-animateContagious InterviewNorth Korea (DPRK)Financial theft & espionage11
TL-2026-11432026-06-21@aifabrix/miso-clientmalicious versionsN/AnpmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-11432026-06-21@iflow-mcp/watercrawl-watercrawl-mcpmalicious versionsN/AnpmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-11432026-06-21@usebioerhold8733/s-format4 incrementally-staged malicious versions published within a 48-hour windowN/AnpmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-11432026-06-21tailwind-autoanimationall published malicious versions injecting payload into src/index.jsN/AnpmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-11432026-06-21tailwind-mainanimationall published malicious versionsremoved by npmnpmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-11432026-06-21tailwindcss-style-animate1.1.6 and re-published malicious versionspackage removed/scrubbed from registrynpmPolinRiderNorth Korea (DPRK)Cryptocurrency theft4
TL-2026-11492026-07-08@injectivelabs/sdk-ts1.20.211.20.23Injective LabsUnattributed
TL-2026-11532026-07-09@injectivelabs/exceptions1.20.211.20.23InjectiveLabsUnattributed
TL-2026-11532026-07-09@injectivelabs/networks1.20.211.20.23InjectiveLabsUnattributed
TL-2026-11532026-07-09@injectivelabs/sdk-ts1.20.211.20.23InjectiveLabsUnattributed
TL-2026-11532026-07-09@injectivelabs/ts-types1.20.211.20.23InjectiveLabsUnattributed
TL-2026-11532026-07-09@injectivelabs/utils1.20.211.20.23InjectiveLabsUnattributed
TL-2026-11532026-07-09@injectivelabs/wallet-base1.20.211.20.23InjectiveLabsUnattributed
TL-2026-11532026-07-09@injectivelabs/wallet-core1.20.211.20.23InjectiveLabsUnattributed
TL-2026-11532026-07-09@injectivelabs/wallet-cosmos1.20.211.20.23InjectiveLabsUnattributed
TL-2026-11532026-07-09@injectivelabs/wallet-cosmos-strategy1.20.211.20.23InjectiveLabsUnattributed
TL-2026-11532026-07-09@injectivelabs/wallet-cosmostation1.20.211.20.23InjectiveLabsUnattributed
TL-2026-11532026-07-09@injectivelabs/wallet-evm1.20.211.20.23InjectiveLabsUnattributed
TL-2026-11532026-07-09@injectivelabs/wallet-ledger1.20.211.20.23InjectiveLabsUnattributed
TL-2026-11532026-07-09@injectivelabs/wallet-magic1.20.211.20.23InjectiveLabsUnattributed
TL-2026-11532026-07-09@injectivelabs/wallet-private-key1.20.211.20.23InjectiveLabsUnattributed
TL-2026-11532026-07-09@injectivelabs/wallet-strategy1.20.211.20.23InjectiveLabsUnattributed
TL-2026-11532026-07-09@injectivelabs/wallet-trezor1.20.211.20.23InjectiveLabsUnattributed
TL-2026-11532026-07-09@injectivelabs/wallet-turnkey1.20.211.20.23InjectiveLabsUnattributed
TL-2026-11532026-07-09@injectivelabs/wallet-wallet-connect1.20.211.20.23InjectiveLabsUnattributed
TL-2026-11642026-07-10jscodeshiftUnattributed
TL-2026-11642026-07-10react-codemodUnattributed
TL-2026-11642026-07-10react-codeshiftUnattributed
TL-2026-12152026-07-11safe-validate1.0.4npm (deepthought26 publisher account)Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-12152026-07-11tailwind-color-shades1.0.2npm (deepthought26 publisher account)Lazarus GroupNorth Korea (DPRK)Financial theft & espionage18
TL-2026-12332026-07-11jscrambler8.14.0, 8.13.08.13.0 (last known-clean; roll back pending official remediation)JscramblerUnattributed
TL-2026-12342026-06-04@vapi-ai/server-sdk0.11.1, 0.11.2, 1.2.1, 1.2.2removed/unpublished versions post-2026-06-04npm (open source)TeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-12342026-06-04ai-sdk-ollama0.13.1, 1.1.1, 2.2.1, 3.8.5removed/unpublished versions post-2026-06-04npm (open source)TeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-12342026-06-04eslint-plugin-awaitlyTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-12342026-06-04executable-stories-cypressTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-12342026-06-04node-env-resolver-awsTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-12342026-06-04wrangler-deployTeamPCPUnknown (cybercrime)Financial (self-propagating worm)40
TL-2026-12382026-07-11jscrambler8.14.08.15.0, 8.13.0 (revert)jscramblerUnattributed
TL-2026-12422026-06-26hexo-deployer-wrangler1.0.4n/a - malicious releasellxlr (npm account)Unattributed
TL-2026-12422026-06-26hexo-shoka-swiper0.1.10n/a - malicious releasellxlr (npm account)Unattributed
TL-2026-12422026-06-26leo-auth4.0.6revert to last known-clean version prior to 2026-06-24LeoPlatform/RStreamsUnattributed
TL-2026-12422026-06-26leo-aws2.0.4pre-2026-06-24 releaseLeoPlatform/RStreamsUnattributed
TL-2026-12422026-06-26leo-cache1.0.2pre-2026-06-24 releaseLeoPlatform/RStreamsUnattributed
TL-2026-12422026-06-26leo-cdk-lib0.0.2pre-2026-06-24 releaseLeoPlatform/RStreamsUnattributed
TL-2026-12422026-06-26leo-cli3.0.3pre-2026-06-24 releaseLeoPlatform/RStreamsUnattributed
TL-2026-12422026-06-26leo-config1.1.1pre-2026-06-24 releaseLeoPlatform/RStreamsUnattributed
TL-2026-12422026-06-26leo-connector-elasticsearch2.0.6pre-2026-06-24 releaseLeoPlatform/RStreamsUnattributed
TL-2026-12422026-06-26leo-connector-mongo3.0.8pre-2026-06-24 releaseLeoPlatform/RStreamsUnattributed
TL-2026-12422026-06-26leo-connector-mysql3.0.3pre-2026-06-24 releaseLeoPlatform/RStreamsUnattributed
TL-2026-12422026-06-26leo-connector-oracle2.0.1pre-2026-06-24 releaseLeoPlatform/RStreamsUnattributed
TL-2026-12422026-06-26leo-connector-redshift3.0.6pre-2026-06-24 releaseLeoPlatform/RStreamsUnattributed
TL-2026-12422026-06-26leo-cron2.0.2pre-2026-06-24 releaseLeoPlatform/RStreamsUnattributed
TL-2026-12422026-06-26leo-logger1.0.8pre-2026-06-24 releaseLeoPlatform/RStreamsUnattributed
TL-2026-12422026-06-26leo-sdk6.0.19pre-2026-06-24 releaseLeoPlatform/RStreamsUnattributed
TL-2026-12422026-06-26leo-streams2.0.1pre-2026-06-24 releaseLeoPlatform/RStreamsUnattributed
TL-2026-12422026-06-26prism-silq1.0.1n/a - malicious releasellxlr (npm account)Unattributed
TL-2026-12422026-06-26rstreams-metrics2.0.2pre-2026-06-24 releaseLeoPlatform/RStreamsUnattributed
TL-2026-12422026-06-26rstreams-shard-util1.0.1pre-2026-06-24 releaseLeoPlatform/RStreamsUnattributed
TL-2026-12422026-06-26serverless-convention2.0.4pre-2026-06-24 releaseLeoPlatform/RStreamsUnattributed
TL-2026-12422026-06-26serverless-leo3.0.14pre-2026-06-24 releaseLeoPlatform/RStreamsUnattributed
TL-2026-12422026-06-26solo-nav1.0.1n/a - malicious releasellxlr (npm account)Unattributed
TL-2026-12422026-06-26verana-blockchainv0.10.1-dev.20revert to clean prior commit/tagVerana LabsUnattributed
TL-2026-12932026-07-14@asyncapi/generator3.3.1AsyncAPI InitiativeMiasma operatorsUnknown (cybercrime)Financial (self-propagating worm)3
TL-2026-12932026-07-14@asyncapi/generator-components0.7.1AsyncAPI InitiativeMiasma operatorsUnknown (cybercrime)Financial (self-propagating worm)3
TL-2026-12932026-07-14@asyncapi/generator-helpers1.1.1AsyncAPI InitiativeMiasma operatorsUnknown (cybercrime)Financial (self-propagating worm)3
TL-2026-12932026-07-14@vapi-ai/server-sdk0.11.1, 0.11.2, 1.2.1, 1.2.2VapiMiasma operatorsUnknown (cybercrime)Financial (self-propagating worm)3
TL-2026-12962026-07-14changiairportpromaxUnattributed
TL-2026-12962026-07-14charlie-kirkUnattributed
TL-2026-12962026-07-14ilovefemboysUnattributed
TL-2026-12962026-07-14miguelphonkUnattributed
TL-2026-12962026-07-14ratelimitsucksUnattributed
TL-2026-12992026-07-14@asyncapi/generator3.3.1unpublished/removed by npm and maintainers post-disclosureAsyncAPI InitiativeUnattributed
TL-2026-12992026-07-14@asyncapi/generator-components0.7.1unpublished/removed by npm and maintainers post-disclosureAsyncAPI InitiativeUnattributed
TL-2026-12992026-07-14@asyncapi/generator-helpers1.1.1unpublished/removed by npm and maintainers post-disclosureAsyncAPI InitiativeUnattributed
TL-2026-12992026-07-14@asyncapi/specs6.11.2, 6.11.2-alpha.1unpublished/removed by npm and maintainers post-disclosureAsyncAPI InitiativeUnattributed
TL-2026-13202026-07-14@asyncapi/generator3.3.13.3.0 (downgrade/pin)AsyncAPI InitiativeUnattributed
TL-2026-13202026-07-14@asyncapi/generator-components0.7.10.7.0 (downgrade/pin)AsyncAPI InitiativeUnattributed
TL-2026-13202026-07-14@asyncapi/generator-helpers1.1.11.1.0 (downgrade/pin)AsyncAPI InitiativeUnattributed
TL-2026-13202026-07-14@asyncapi/specs6.11.2, 6.11.2-alpha.16.11.1 (downgrade/pin)AsyncAPI InitiativeUnattributed
TL-2026-13602026-07-15@asyncapi/generator3.3.13.3.0 (rollback)AsyncAPI InitiativeUnattributed
TL-2026-13602026-07-15@asyncapi/generator-components0.7.11.0.0AsyncAPI InitiativeUnattributed
TL-2026-13602026-07-15@asyncapi/generator-helpers1.1.11.1.0 (rollback)AsyncAPI InitiativeUnattributed
TL-2026-13602026-07-15@asyncapi/specs6.11.2, 6.11.2-alpha.16.11.1 (rollback)AsyncAPI InitiativeUnattributed
TL-2026-13792026-07-15jscrambler8.14.0, 8.16.0, 8.17.0, 8.18.0, 8.20.08.22.0JscramblerUnattributed
TL-2026-13812026-07-15@injectivelabs/exceptions1.20.211.20.23 or laterInjective LabsUnattributed
TL-2026-13812026-07-15@injectivelabs/networks1.20.211.20.23 or laterInjective LabsUnattributed
TL-2026-13812026-07-15@injectivelabs/sdk-ts1.20.211.20.23Injective LabsUnattributed
TL-2026-13812026-07-15@injectivelabs/ts-types1.20.211.20.23 or laterInjective LabsUnattributed
TL-2026-13812026-07-15@injectivelabs/utils1.20.211.20.23 or later, or unpin from malicious versionInjective LabsUnattributed
TL-2026-13812026-07-15@injectivelabs/wallet-base1.20.211.20.23 or laterInjective LabsUnattributed
TL-2026-13812026-07-15@injectivelabs/wallet-core1.20.211.20.23 or laterInjective LabsUnattributed
TL-2026-13812026-07-15@injectivelabs/wallet-cosmos1.20.211.20.23 or laterInjective LabsUnattributed
TL-2026-13812026-07-15@injectivelabs/wallet-cosmos-strategy1.20.211.20.23 or laterInjective LabsUnattributed
TL-2026-13812026-07-15@injectivelabs/wallet-cosmostation1.20.211.20.23 or laterInjective LabsUnattributed
TL-2026-13812026-07-15@injectivelabs/wallet-evm1.20.211.20.23 or laterInjective LabsUnattributed
TL-2026-13812026-07-15@injectivelabs/wallet-ledger1.20.211.20.23 or laterInjective LabsUnattributed
TL-2026-13812026-07-15@injectivelabs/wallet-magic1.20.211.20.23 or laterInjective LabsUnattributed
TL-2026-13812026-07-15@injectivelabs/wallet-private-key1.20.211.20.23 or laterInjective LabsUnattributed
TL-2026-13812026-07-15@injectivelabs/wallet-strategy1.20.211.20.23 or laterInjective LabsUnattributed
TL-2026-13812026-07-15@injectivelabs/wallet-trezor1.20.211.20.23 or laterInjective LabsUnattributed
TL-2026-13812026-07-15@injectivelabs/wallet-turnkey1.20.211.20.23 or laterInjective LabsUnattributed
TL-2026-13812026-07-15@injectivelabs/wallet-wallet-connect1.20.211.20.23 or laterInjective LabsUnattributed
TL-2026-13872026-07-15@asyncapi/generator3.3.13.3.0AsyncAPI InitiativeUnattributed
TL-2026-13872026-07-15@asyncapi/generator-components0.7.11.0.0AsyncAPI InitiativeUnattributed
TL-2026-13872026-07-15@asyncapi/generator-helpers1.1.11.1.0AsyncAPI InitiativeUnattributed
TL-2026-13872026-07-15@asyncapi/specs6.11.2-alpha.1, 6.11.26.11.1 or earlierAsyncAPI InitiativeUnattributed

Sorted by threat ID (Threadlinqs TL number). Click any column header to re-sort; type to filter. Every TL number links to the full enriched threat record; every package links to its npm registry page; every attributed actor links to its actor profile. Vulnerable/fixed versions mirror each threat's // affected section. “Actor threats” is the number of threats attributed to that actor across the Threadlinqs corpus.

How to protect against npm supply chain attacks: a checklist

Prioritized for a security team working from the top down:

Frequently asked questions

What is an npm supply chain attack?

An npm supply chain attack compromises a trusted package in the npm registry — by stealing a maintainer's publish token, hijacking a dormant account, or poisoning the CI/CD pipeline that publishes it — so that every project installing the package also pulls attacker code. Because a single popular package can be a dependency of millions of projects, one compromise cascades across the ecosystem.

How many npm packages were compromised in 2026?

Between February 1 and July 15, 2026, Threadlinqs Intelligence documented 78 distinct npm supply chain attacks involving 218 unique malicious packages across 308 documented package records. The full, sortable list — with vulnerable and fixed versions and the attributed threat actor — is in the master table on this page.

What is the Shai-Hulud npm worm?

Shai-Hulud is a family of self-replicating npm worms — including Mini Shai-Hulud, Miasma, Hades, and the compiled-Rust IronWorm — that harvest cloud and CI credentials at install time and then auto-republish through the maintainer accounts they just stole from. It is the first true worm behavior in the npm ecosystem, turning one compromise into self-propagating malware. Threadlinqs links the lineage to a crew tracked as TeamPCP, present in 40 of the 78 documented attacks.

Who is behind the 2026 npm supply chain attacks?

Attribution splits two ways. North Korea (DPRK) accounts for 23 of the 78 attacks (56% of those with a named actor), spread across the UNC1069/Sapphire Sleet, APT38, Lazarus Group, Contagious Interview, WageMole, and PolinRider clusters, motivated by cryptocurrency and credential theft. The other pole is financially motivated crimeware led by TeamPCP and its self-replicating worm family.

What is a binding.gyp "Phantom Gyp" attack?

Phantom Gyp is an install-time execution technique that avoids the obvious postinstall hook. An attacker drops a small binding.gyp file into a pure-JavaScript package; npm then invokes node-gyp during install, and node-gyp's command-substitution syntax executes attacker code without any lifecycle script being declared. The Miasma worm used a 157-byte binding.gyp to trojanize dozens of packages across hundreds of versions.

What is slopsquatting?

Slopsquatting (also called HalluSquatting) is a name-based attack that weaponizes AI: attackers pre-register the plausible-but-nonexistent package names that large language models hallucinate, so that when an AI coding assistant confidently suggests one of those names, the developer installs attacker-controlled code. It is typosquatting adapted to the era of AI-generated dependency suggestions.

How do I protect against npm supply chain attacks?

Enforce package provenance (npm audit signatures and SLSA), set --ignore-scripts by default in CI, pin exact versions with integrity hashes in committed lockfiles, scope publish tokens narrowly and prefer short-lived OIDC over legacy tokens, revoke dormant maintainer access, and adopt the npm 12 defaults that disable lifecycle scripts, node-gyp, Git dependencies, and remote tarballs. The remediation checklist on this page prioritizes these for a security team.

Track this in real time

Threadlinqs Intelligence tracks npm supply chain compromises as they happen — every package, version, IOC, detection rule, and threat actor, enriched and cross-linked. This article is a snapshot; the platform is live and updated nightly.

Start a free 7-day trial of Purple — the full detection library, real-time IOC enrichment, MCP access, and the correlation engine. Create an account to begin; no card required to start the trial.

[ start_free_7_day_trial ]

Sources and further reading