Between February 1 and July 15, 2026, Threadlinqs Intelligence documented 78 npm supply chain attacks spanning 218 malicious npm packages — self-replicating worms, CI/CD pipeline hijacks, AI-agent credential theft, and industrialized DPRK campaigns. Two throughlines dominate the window: a single crimeware crew, TeamPCP, linked to 40 of the 78 threats through the Shai-Hulud worm lineage, and North Korea, behind 23. This is the full reference: every wave, every technique, and every documented package, each mapped back to its threat record and attributed actor.
npm supply chain attacks by the numbers
- Window: February 1 – July 15, 2026 (5.5 months)
- Documented threats: 78
- Distinct malicious packages: 218
- Package IOCs recorded: 316
- Threats with a named actor: 41 of 78
- DPRK-attributed threats: 23 (29% of all; 56% of the attributed subset)
- Distinct threat actors tracked: 12
- Master-list records (documented package × threat): 308
- TeamPCP-linked threats (the worm lineage): 40
Timeline: the major npm supply chain attacks of 2026
| Date | Wave | Threats | What happened |
|---|---|---|---|
| Mar 2026 | PolinRider VS Code auto-run + blockchain dead-drops | TL-2026-0437 | DPRK implants spread across 1,951 GitHub repos via Tailwind/PostCSS typosquats and weaponized .vscode/tasks.json, resolving C2 from TRON/Aptos/BSC blockchains. |
| 2026-03-11 | prt-scan GitHub Actions pwn-request campaign | TL-2026-0318 | One actor with six disposable accounts opened malicious PRs against 500+ repos to exploit pull_request_target and exfiltrate CI/CD secrets in public logs (ran through Apr 3). |
| Apr 2026 | Axios compromise by UNC1069 / Sapphire Sleet | TL-2026-0305, TL-2026-0311, TL-2026-0397, TL-2026-0351 | A stolen legacy token honored over OIDC published backdoored axios via phantom dependency plain-crypto-js (~600K downloads in 3h); reached OpenAI's macOS signing pipeline, forcing cert rotation. CISA alert 04-20. |
| Apr 2026 | TeamPCP cascading Bitwarden/Checkmarx breach | TL-2026-0425, TL-2026-0429 | Reused credentials from the Checkmarx breach poisoned checkmarx/ast-github-action to publish trojanized @bitwarden/cli, harvesting live vault exports and AI-tool configs. CISA AA26-115A. |
| Apr 2026 | Mini Shai-Hulud worm: SAP, Intercom, TanStack, @antv | TL-2026-0439, TL-2026-0446, TL-2026-0499, TL-2026-0530, TL-2026-0547 | TeamPCP worm hit SAP CAP, intercom-client, @tanstack/react-router (~12M wk dl) and 200+ @antv packages using Bun-runtime execution, orphan-commit staging and OIDC token theft. |
| May 2026 | node-ipc backdoor + Megalodon mass-repo worm | TL-2026-0518, TL-2026-0556, TL-2026-0557 | node-ipc backdoor (require-triggered, DNS-TXT exfil); Megalodon pushed workflow-injection commits to 5,561 GitHub repos in 6 hours, bleeding into npm via @tiledesk/tiledesk-server. |
| May 2026 | Cross-ecosystem stealers + cloud-secret typosquats | TL-2026-0576, TL-2026-0623, TL-2026-0633 | TrapDoor coordinated 34 packages across npm/PyPI/crates.io with zero-width AI-assistant injection; Microsoft flagged typosquat and dependency-confusion packages sweeping AWS/Vault/CI secrets. |
| May 2026 | AI becomes a target: Claude sandbox + Codex/MCP | TL-2026-0621, TL-2026-0641, TL-2026-0712 | AI-generated "Malware-Slop" exfiltrated Claude's /mnt/user-data sandbox; codexui-android stole Codex OAuth tokens; a Mitiga PoC hijacked Claude Code MCP traffic for OAuth theft. |
| Jun 2026 | Miasma resurgence: RedHat, Microsoft repos, Phantom Gyp | TL-2026-0643, TL-2026-0733, TL-2026-1234, TL-2026-0963, TL-2026-1293 | TeamPCP's Miasma worm poisoned @redhat-cloud-services and 73 Microsoft repos, introduced the binding.gyp "Phantom Gyp" vector (57 pkgs/286 versions) and abused the npm bypass_2fa API. |
| 2026-06-17 | Mastra AI-framework mass-republish | TL-2026-0898, TL-2026-0836, TL-2026-0977 | Sapphire Sleet hijacked the dormant ehindero account and republished 140+ @mastra packages (@mastra/core ~918K wk dl) in an ~88-minute burst, injecting the easy-day-js typosquat dependency. |
| Jun 2026 | Injective SDK wallet backdoor + Atomic Arch AUR pivot | TL-2026-1153, TL-2026-1149, TL-2026-0788, TL-2026-0979 | 18 @injectivelabs packages backdoored to steal BIP-39 mnemonics via fake telemetry and HTTP-header exfil; Atomic Arch hijacked 400+ AUR packages to pull malicious npm packages with an eBPF rootkit. |
| Jun–Jul 2026 | PolinRider cross-ecosystem expansion | TL-2026-1055, TL-2026-1120, TL-2026-1143, TL-2026-1215 | DPRK PolinRider scaled to 108 malicious packages/extensions (162 artifacts) across npm, Packagist, Go and the Chrome Web Store, with blockchain dead-drop C2 and build-config injection persistence. |
| Jul 2026 | AsyncAPI pwn-request → SLSA-signed Miasma | TL-2026-1360, TL-2026-1299, TL-2026-1320, TL-2026-1387 | An unpatched pull_request_target flaw stole the asyncapi-bot PAT; the project's own OIDC trusted-publishing shipped five malicious @asyncapi versions (~2.9M wk dl) with valid provenance, delivering Miasma at import time. |
| 2026-07-11 | jscrambler / IronWorm security-vendor compromise | TL-2026-1379, TL-2026-1233, TL-2026-1238 | A stolen credential published five malicious jscrambler versions (8.14.0–8.20.0) dropping IronWorm, a Rust cross-platform stealer in the Shai-Hulud lineage; flagged in 6 minutes yet republished over 3 hours. |
| Jul 2026 | Ecosystem response + AI-native research | TL-2026-1163, TL-2026-1164 | npm 12 disabled lifecycle scripts, node-gyp, Git deps and remote tarballs by default (opt-in allowlist); researchers demonstrated HalluSquatting, pre-registering LLM-hallucinated names that nine AI coding assistants fetch. |
How npm supply chain attacks changed in 2026: the novel techniques
The window's defining shift is that npm stopped being a place where attackers drop a single poisoned package and wait. It became a medium for self-propagating malware, a lever on the pipelines that publish, and a channel to reach AI agents. Eight technique families account for nearly everything documented.
Self-replicating npm worms — the Shai-Hulud lineage
For most of npm's history a compromise was a discrete event: one package, one bad version, one takedown. That model broke down with the Shai-Hulud worm family — the original Shai-Hulud first appeared in late 2025, and Mini Shai-Hulud, Miasma, Hades, and the compiled IronWorm escalated it sharply across this window — worms that harvest cloud and CI credentials at install time and then auto-republish through the very maintainers they just robbed. Socket and StepSecurity tracked the worm family to a crew tracked as TeamPCP, which Threadlinqs links to 40 of the 78 threats in the window; the Shai-Hulud and Miasma generations are carried as distinct operator labels within that lineage rather than as confirmed TeamPCP aliases.
The novelty is closed-loop propagation. Each generation kept the harvest-and-republish core while iterating tradecraft: Bun-runtime execution to sidestep Node tooling, orphan-commit payload staging so the malicious code never appears in the visible Git history, and TruffleHog secret sweeps across the compromised host. Miasma trojanized 57 npm packages across 286+ versions using a 157-byte binding.gyp "Phantom Gyp" that runs a 4–5MB ROT-N-obfuscated index.js during install, harvests AWS/GCP/Azure/Vault/Kubernetes/GitHub-Actions credentials, then propagates across CI/CD (TL-2026-1234). By July the lineage had crossed into compiled Rust with IronWorm (TL-2026-1379), hardening the payload against JavaScript-level scanners entirely.
Install-time and import-time execution without a visible install script
Attackers systematically abandoned the obvious postinstall hook — the first thing any scanner checks — for triggers that evade install-script analysis. Phantom Gyp is the standout: drop a binding.gyp into a pure-JS package and npm invokes node-gyp, whose command-substitution syntax executes code with no lifecycle script declared at all. Others moved execution into module require()/import (with sideEffects arrays to defeat tree-shaking), into preinstall so theft fires before code even unpacks, or into a downloaded Bun runtime that never touches Node-level tooling.
node-ipc 9.1.6/9.2.3/12.0.1 (~822K weekly downloads) fired its credential stealer on module require() rather than any lifecycle script, exfiltrating cloud, SSH, Kubernetes, and Terraform secrets over DNS TXT queries (TL-2026-0518). This pressure was the direct cause of npm 12 flipping lifecycle scripts, node-gyp, Git dependencies, and remote tarballs to opt-in (TL-2026-1163).
CI/CD trusted publishing as the new blast radius
The highest-leverage attacks stopped stealing npm tokens and hijacked the pipelines that publish. The recurring primitive is the GitHub Actions "pwn-request": a pull_request_target workflow that checks out untrusted PR code while holding base-repo secrets. From there, operators read OIDC tokens out of runner memory (/proc/<pid>/mem) and publish through the project's own trusted-publisher workflow — so the poisoned tarball carries valid SLSA provenance.
The AsyncAPI compromise is the clean example: an unpatched pull_request_target flaw leaked the asyncapi-bot PAT, then npm OIDC trusted publishing shipped five malicious @asyncapi versions (~2.9M weekly downloads) with provenance attesting the workflow, not the malicious commit (TL-2026-1360, TL-2026-1299). Automated worms weaponized the same primitive at scale: Megalodon touched 5,561 repos in six hours (TL-2026-0556) and a poisoned codfish/semantic-release-action exposed 1,442 repos. The Axios compromise took a different route — a stolen legacy NPM_TOKEN published the backdoor, which then reached OpenAI's macOS signing pipeline through a floating ^1.14.0 version range in the signing CI (TL-2026-0351), forcing an Apple Developer ID certificate rotation.
AI as both target and weapon
2026 is where AI entered the supply chain from both directions at once. As a target, AI-agent credentials and configs became the prize: OpenAI Codex OAuth tokens, Claude Code MCP OAuth bearer tokens, the Claude sandbox filesystem, and whole frameworks (Mastra, @mistralai). A Mitiga PoC's postinstall hook rewrote mcpServers URLs in ~/.claude.json to route Claude Code's MCP traffic through an attacker mitmproxy, seeded directory-trust flags, and injected a SessionStart hook to steal persistent OAuth bearer tokens for Jira and GitHub over MCP (TL-2026-0712).
As a weapon, AI generated the malware ("slop" packages, language-aware payloads), pre-registered the plausible package names that LLMs hallucinate so coding agents fetch them — a technique now called slopsquatting or HalluSquatting — and manipulated the LLM reviewers themselves. The package shai_hulululud embedded a fake SYSTEM-OVERRIDE prompt-injection and token-flooding to blind LLM scanners (TL-2026-0829). Socket, which first flagged the package, detailed the same prompt-injection technique. It is defense being attacked at its own layer.
Maintainer-trust and account-takeover tradecraft
Rather than exploit code, attackers exploited the trust model around publishing. Documented techniques include a stolen legacy NPM_TOKEN being honored over OIDC Trusted Publishing (bypassing 2FA), dormant contributor access that was never revoked, expired recovery-domain re-registration, social-engineered maintainer handovers, and abuse of the npm bypass_2fa API.
Nearly universal was "phantom-dependency injection" paired with "clean-decoy pre-staging": leave the trusted package's own code untouched and hide the malice one hop away, in a freshly added dependency whose benign decoy version was published hours earlier to defeat novelty heuristics. Backdoored axios@1.14.1/0.30.4 were bit-for-bit identical to the clean releases except one package.json line adding phantom dependency plain-crypto-js@^4.2.1, whose clean 4.2.0 decoy had been staged roughly 18 hours earlier; the maintainer's stolen legacy token was honored over OIDC despite MFA (TL-2026-0305, TL-2026-0397).
Novel C2 and exfiltration channels
Operators fled takedown-prone domains for infrastructure that is immutable, decentralized, or indistinguishable from legitimate traffic. Blockchain dead-drops resolved C2 that cannot be seized: PolinRider's tailwind-color-shades/safe-validate loaders queried TRON and Aptos and decrypted an XOR payload from Binance Smart Chain burn-address transactions — "EtherHiding" — to resolve C2 with no static domain (TL-2026-1215). Legitimate services became payload hosts (Hugging Face, IPFS, GitHub Releases and the Contents API, jsonkeeper and rentry pastes).
Exfiltration hid where egress filters do not look. The @injectivelabs backdoor base64-encoded stolen BIP-39 mnemonics into the X-Request-Id HTTP header, shaped to resemble gRPC-Web traffic (TL-2026-1149). Others used DNS TXT queries, WebRTC P2P, and Cloudflare Worker proxies to survive egress filtering.
DPRK industrialization of developer-targeting campaigns
North Korea moved from bespoke drops to automated malware factories. The Contagious Interview, PolinRider, and WageMole clusters mass-produced malicious packages in escalating waves — 67, then 108-package/261-version runs, then ~200-package OtterCookie batches — delivered through fake-recruiter coding-assessment lures on LinkedIn, Fiverr, and Upwork, plus brandjacking, VS Code tasks.json folderOpen auto-run, malicious git pre-commit hooks, and backdoored IDE-marketplace extensions.
PolinRider published 108 malicious packages and extensions across 162 artifacts spanning npm, Packagist, 80+ Go modules, and the Chrome Web Store, appending obfuscated JS to build-config files (tailwind.config.js, next.config.mjs) and abusing .vscode/tasks.json runOn: folderOpen to auto-run BeaverTail/InvisibleFerret the moment a repo opened (TL-2026-1055, TL-2026-1143). DPRK accounts drove 23 of the 78 threats, and the crypto-theft subset (UNC1069 and PolinRider) went straight for wallet keys.
Typosquatting, dependency-confusion, and cross-ecosystem registry abuse
The classic name-based vectors persisted but grew more sophisticated: inflated version numbers to win dist-tag resolution, brandjacking via suffix or embedding rather than raw typos, dependency-confusion against real internal corporate namespaces, and coordination across npm, PyPI, crates.io, Go, and the AUR under one toolchain. Two newer twists stand out. The Atomic Arch campaign legitimately adopted 400+ (later 1,500+) orphaned AUR packages and modified their PKGBUILD hooks to run npm install atomic-lockfile@1.4.2, whose preinstall hook executes a bundled Rust ELF that steals credentials and installs an eBPF rootkit — a Linux distro repo bridged into npm (TL-2026-0788, TL-2026-0979). Separately, operators abused the npm registry itself as a free CDN, hosting adware and DDoS-botnet payloads in packages with no install hook at all.
Who is behind the npm supply chain attacks?
North Korea dominates. Of the 78 threats, 23 (29%) are DPRK-attributed; of the 41 with a named actor, 23 (56%) trace to DPRK clusters. The rest of the attributed set is financially motivated crimeware, and 37 threats carry no confident attribution at all.
The DPRK clusters overlap by design. Lazarus Group carries the most links (18 threats), reflecting its role as the umbrella under which the sub-clusters operate. Contagious Interview (11 threats) runs the fake-recruiter coding-assessment lures. WageMole (10) handles the IT-worker fraud angle. UNC1069 — the Sapphire Sleet cluster — and APT38 (9 each) drive the financially motivated theft, with UNC1069 behind the Axios and Mastra compromises. PolinRider (4) is the crypto-theft and cross-ecosystem specialist. The unifying motive is money — cryptocurrency wallet keys and developer credentials that convert to access — not espionage in the traditional sense.
The financially motivated crimeware side is defined by one crew. TeamPCP is the single biggest throughline in the entire dataset, linked to 40 threats via the self-replicating worm family. Where DPRK mass-produces discrete packages, TeamPCP built self-propagating malware — the difference between a factory and a contagion. The Shai-Hulud operators (4) and Miasma operators (3) are tracked as related-but-distinct labels for generations of the same lineage. ShinyHunters (15) surfaces around the data-theft and extortion tail, and TrapDoor and PhantomRaven (1 each) round out the cross-ecosystem crypto-stealer crews.
Attribution here is provisional. Worms muddy it further: once a self-propagating payload harvests one maintainer's token and republishes, the "actor" behind a given malicious version may be an automated loop rather than a human operator making a decision. Treat the named-actor column in the master list as an assessment, not a verdict.
How to detect and prevent npm supply chain attacks
The following detections are drawn from the Threadlinqs platform and map to the threats above. Trim the field names to your schema.
Mini Shai-Hulud fires its payload from a lifecycle hook spawning node/bun/python on a staged script — the earliest observable in the kill chain (TL-2026-0446):
sigmatitle: Mini Shai-Hulud npm/pip Preinstall Hook Spawns node-bun on setup.mjs or router_runtime.js
status: experimental
description: Detects npm/yarn/pnpm/pip lifecycle hooks invoking node, bun, or python on
setup.mjs, router_runtime.js, or the Mini Shai-Hulud trojanized packages (intercom-client,
@cap-js/*, mbt, lightning).
references:
- https://socket.dev/blog/intercom-s-npm-package-compromised-in-supply-chain-attack
logsource:
category: process_creation
The credential sweep that follows install — a node/bun process reading .npmrc, .aws/credentials, .kube/config, .vault-token, and terraform.tfstate within minutes of an install firing (TL-2026-0446):
kqllet credPaths = dynamic([".npmrc", ".yarnrc", "hosts.yml", ".docker/config.json",
".aws/credentials", ".kube/config", ".vault-token", ".env", ".envrc",
"terraform.tfstate", ".gitconfig"]);
DeviceFileEvents
| where Timestamp > ago(24h)
| where ActionType in ("FileAccessed", "FileOpened", "FileRead")
| where InitiatingProcessFileName has_any ("node", "node.exe", "bun", "bun.exe",
"python", "python3", "npm", "npm.cmd")
| where FileName has_any (credPaths)
Worm propagation is visible as a burst of patch-version publishes from a maintainer dormant for 30+ days, or GitHub repos created with the worm's signature description (TL-2026-0446):
kqllet poisonRepoPrefixes = dynamic(["ghola-melange-", "mentat-melange-", "powindah-sietch-"]);
let poisonDescription = "A Mini Shai-Hulud has Appeared";
GitHubAuditLog_CL
| where TimeGenerated > ago(24h)
| where action_s in ("repo.create", "repo.transfer", "public_repo.create")
| extend RepoName = tostring(repo_s), Description = tostring(description_s)
| where Description has poisonDescription
or RepoName startswith_cs "ghola-melange-"
For the AI-agent surface, watch MCP config files in AI coding-assistant directories for injection (TL-2026-0147):
kqlDeviceFileEvents
| where Timestamp > ago(24h)
| where FolderPath has_any (".claude", ".cursor", ".continue", ".codeium", ".windsurf")
| where FileName in~ ("settings.json", "mcp.json", "config.json", "mcp_config.json")
| where ActionType in ("FileCreated", "FileModified")
And the exfil tail — Node fetching Pastebin raw URLs mid-install as a dead-drop C2 resolver (TL-2026-0152):
splindex=proxy sourcetype="bluecoat:proxysg:access:syslog" OR sourcetype="squid:access"
| search cs_host="pastebin.com" cs_uri_path="/raw/*"
| eval is_known_deaddrop=if(match(cs_uri_path, "(CJ5PrtNk|0ec7i68M|DjDCxcsT)"), 1, 0)
| stats count as paste_fetches, sum(is_known_deaddrop) as known_hits by src_ip, cs_User_Agent
| where paste_fetches >= 1
Beyond detection, the hygiene that would have blunted most of this window:
- Enforce provenance. Require
npm audit signaturesand reject packages without valid SLSA provenance — noting that provenance attests the workflow, not intent, so pair it with publish-source review. --ignore-scriptsby default. Disable lifecycle scripts in CI and local installs; adopt an explicit opt-in allowlist for the handful of packages that genuinely need them.- Pin and verify. Commit lockfiles, pin exact versions, and enforce
integrityhashes; do not float dependency ranges that let a phantom dependency slip in. - Least-privilege CI tokens. Scope publish tokens narrowly, prefer short-lived OIDC over long-lived legacy tokens, and revoke dormant maintainer and contributor access on a schedule.
- Adopt the npm 12 defaults. Lifecycle scripts, node-gyp, Git dependencies, and remote tarballs are now opt-in — keep them off and allowlist deliberately.
Every documented npm package: the master list
The table below is the full package-level record for the window — every documented malicious package and version, sorted by TL number, each row linking to its threat and enriched with the attributed actor and that actor's country and motive. Use it as a blocklist source and a triage reference; the "Actor" column is an assessment, not a confirmed verdict.
| TL # | Published | Package | Vulnerable | Fixed | Patched | Vendor / namespace | Threat actor | Country | Motive | Actor threats |
|---|---|---|---|---|---|---|---|---|---|---|
| TL-2026-0231 | 2026-03-15 | @aifabrix/miso-client | 4.7.2 | — | ✗ | @aifabrix | PhantomRaven | Unknown (cybercrime) | Financial (credential theft) | 1 |
| TL-2026-0231 | 2026-03-15 | @iflow-mcp/watercrawl-watercrawl-mcp | 1.3.0-1.3.4 | — | ✗ | @iflow-mcp | PhantomRaven | Unknown (cybercrime) | Financial (credential theft) | 1 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/account-sdk | 1.41.1, 1.41.2 | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/account-sdk-node | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/accounting-sdk-node | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/api-documentation | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/auth-sdk | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/auth-sdk-node | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/billing-sdk | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/billing-sdk-node | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/claim-sdk | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/claim-sdk-node | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/customer-sdk | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/customer-sdk-node | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/document-sdk | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/document-sdk-node | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/gdv-sdk | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/insurance-sdk | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/insurance-sdk-node | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/notification-sdk-node | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/partner-portal-sdk-node | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/partner-sdk-node | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/payment-sdk | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/payment-sdk-node | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/process-manager-sdk-node | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/public-api-sdk | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/public-api-sdk-node | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/tenant-sdk | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/tenant-sdk-node | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @emilgroup/translation-sdk-node | patch .x.1, .x.2 versions | — | ✗ | emilgroup | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0259 | 2026-03-20 | @teale.io/eslint-config | 1.8.9, 1.8.10 | — | ✗ | teale.io | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0279 | 2026-03-24 | ast-github-action | v2.3.28 | — | ✗ | Checkmarx | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0279 | 2026-03-24 | kics-github-action | v1.1 | — | ✗ | Checkmarx | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0279 | 2026-03-24 | setup-trivy | 0.2.0-0.2.6 (original) | 0.2.6 (recreated) | ✓ | Aqua Security | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0279 | 2026-03-24 | trivy-action | 0.0.1-0.34.2 (76 tags) | 0.35.0 | ✓ | Aqua Security | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0300 | 2026-03-30 | axios | 1.14.1, 0.30.4 | 1.14.0, 0.30.3 | ✓ | axios | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0300 | 2026-03-30 | plain-crypto-js | 4.2.1 | — | ✗ | nrwise | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0301 | 2026-03-31 | @qqbrowser/openclaw-qbot | 0.0.130 | — | ✗ | qqbrowser | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0301 | 2026-03-31 | @shadanai/openclaw | 2026.3.28-2, 2026.3.28-3, 2026.3.31-1, 2026.3.31-2 | — | ✗ | shadanai | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0301 | 2026-03-31 | axios | 1.14.1, 0.30.4 | 1.14.0, 0.30.3 | ✓ | axios | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0301 | 2026-03-31 | plain-crypto-js | 4.2.1 | — | ✗ | nrwise | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0303 | 2026-03-31 | @qqbrowser/openclaw-qbot | 0.0.130 | Package reported for removal | ✓ | npm | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0303 | 2026-03-31 | @shadanai/openclaw | 2026.3.28-2, 2026.3.28-3, 2026.3.31-1, 2026.3.31-2 | Package reported for removal | ✓ | npm | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0303 | 2026-03-31 | axios | 1.14.1, 0.30.4 | All other versions (malicious versions unpublished) | ✓ | axios | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0303 | 2026-03-31 | plain-crypto-js | 4.2.1 | Package removed from npm | ✓ | npm | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0305 | 2026-03-31 | @qqbrowser/openclaw-qbot | 0.0.130 | — | ✗ | npm | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0305 | 2026-03-31 | @shadanai/openclaw | 2026.3.31-1, 2026.3.31-2 | — | ✗ | npm | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0305 | 2026-03-31 | axios | 1.14.1, 0.30.4 | 1.14.2, 1.14.0, 0.30.3 | ✓ | axios | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0305 | 2026-03-31 | plain-crypto-js | 4.2.1 | — | ✗ | npm | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0309 | 2026-04-01 | axios | 1.14.1, 0.30.4 | 1.14.0, 0.30.3 | ✓ | axios | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0309 | 2026-04-01 | plain-crypto-js | all | removed from npm | ✓ | unknown | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0311 | 2026-04-01 | @qqbrowser/openclaw-qbot | 0.0.130 | — | ✗ | npm | APT38 | North Korea (DPRK) | Financial theft | 9 |
| TL-2026-0311 | 2026-04-01 | @shadanai/openclaw | 2026.3.28-2, 2026.3.28-3, 2026.3.31-1, 2026.3.31-2 | — | ✗ | npm | APT38 | North Korea (DPRK) | Financial theft | 9 |
| TL-2026-0311 | 2026-04-01 | axios | 1.14.1, 0.30.4 | 1.14.2, 0.30.3 | ✓ | axios | APT38 | North Korea (DPRK) | Financial theft | 9 |
| TL-2026-0311 | 2026-04-01 | plain-crypto-js | 4.2.1 | — | ✗ | npm | APT38 | North Korea (DPRK) | Financial theft | 9 |
| TL-2026-0314 | 2026-04-02 | axios | 1.14.1, 0.30.4 | 1.14.2, 0.30.5 | ✓ | axios | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0314 | 2026-04-02 | plain-crypto-js | 4.2.1 | — | ✗ | npm | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0332 | 2026-04-07 | express-session-js | — | — | ✓ | — | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0332 | 2026-04-07 | graphalgo | — | — | ✓ | — | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0332 | 2026-04-07 | react-plaid-sdk | — | — | ✓ | — | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0351 | 2026-04-11 | axios | 1.14.1, 0.30.4 | 1.14.0, 0.30.3 | ✓ | axios | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0351 | 2026-04-11 | plain-crypto-js | 4.2.1, 4.2.0 | — | ✗ | Unknown (malicious) | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0397 | 2026-04-20 | axios | 1.14.1, 0.30.4 | 1.14.0, 0.30.3 | ✓ | Axios | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0397 | 2026-04-20 | plain-crypto-js | 4.2.1, 4.2.0 | 0.0.1-security.0 (npm security-holder stub) | ✓ | nrwise (attacker-controlled) | UNC1069 | North Korea (DPRK) | Cryptocurrency theft | 9 |
| TL-2026-0425 | 2026-04-27 | @bitwarden/cli | 2026.4.7 | 2026.4.8, 2026.4.6 | ✓ | Bitwarden | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0429 | 2026-04-27 | @bitwarden/cli | 2026.4.0 | 2026.4.1 | ✓ | Bitwarden | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0437 | 2026-04-29 | tailwind-animationbased | all | — | ✗ | npm Inc. (registry) | PolinRider | North Korea (DPRK) | Cryptocurrency theft | 4 |
| TL-2026-0437 | 2026-04-29 | tailwind-autoanimation | 2.3.6 | — | ✗ | npm Inc. (registry) | PolinRider | North Korea (DPRK) | Cryptocurrency theft | 4 |
| TL-2026-0437 | 2026-04-29 | tailwind-mainanimation | 2.3.3 | — | ✗ | npm Inc. (registry) | PolinRider | North Korea (DPRK) | Cryptocurrency theft | 4 |
| TL-2026-0437 | 2026-04-29 | tailwindcss-animate-style | all | — | ✗ | npm Inc. (registry) | PolinRider | North Korea (DPRK) | Cryptocurrency theft | 4 |
| TL-2026-0437 | 2026-04-29 | tailwindcss-style-animate | 1.1.6 | — | ✗ | npm Inc. (registry) | PolinRider | North Korea (DPRK) | Cryptocurrency theft | 4 |
| TL-2026-0437 | 2026-04-29 | tailwindcss-style-modify | 0.8.3 | — | ✗ | npm Inc. (registry) | PolinRider | North Korea (DPRK) | Cryptocurrency theft | 4 |
| TL-2026-0437 | 2026-04-29 | tailwindcss-typography-style | 0.8.2 | — | ✗ | npm Inc. (registry) | PolinRider | North Korea (DPRK) | Cryptocurrency theft | 4 |
| TL-2026-0439 | 2026-04-30 | @cap-js/db-service | 2.10.1 | — | ✗ | SAP cap-js | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0439 | 2026-04-30 | @cap-js/postgres | 2.2.2 | — | ✗ | SAP cap-js | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0439 | 2026-04-30 | @cap-js/sqlite | 2.2.2 | — | ✗ | SAP cap-js | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0439 | 2026-04-30 | mbt | 1.2.48 | — | ✗ | — | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0446 | 2026-04-30 | @cap-js/db-service | 2.10.1 | post-2.10.1 | ✓ | SAP | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0446 | 2026-04-30 | @cap-js/postgres | 2.2.2 | post-2.2.2 | ✓ | SAP | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0446 | 2026-04-30 | @cap-js/sqlite | 2.2.2 | post-2.2.2 | ✓ | SAP | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0446 | 2026-04-30 | intercom-client | 7.0.4 | 7.0.5+ | ✓ | Intercom | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0446 | 2026-04-30 | lightning | 2.6.2, 2.6.3 | 2.6.1, 2.6.4+ | ✓ | Lightning AI | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0446 | 2026-04-30 | mbt | 1.2.48 | — | ✗ | — | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0499 | 2026-05-12 | @mistralai/mistralai | 2.2.2, 2.2.3, 2.2.4 | — | ✗ | Mistral AI | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0499 | 2026-05-12 | @tanstack/react-router | 1.169.5, 1.169.8 | — | ✗ | TanStack | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0499 | 2026-05-12 | guardrails-ai | 0.10.1 | — | ✗ | Guardrails AI | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0499 | 2026-05-12 | mistralai | 2.4.6 | — | ✗ | Mistral AI | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0518 | 2026-05-15 | node-ipc | 9.1.6, 9.2.3, 12.0.1 | any clean release reverted post-incident; pin to <= 9.2.2 or >= 12.0.2 with verified integrity hash | ✓ | node-ipc maintainers (npm) | Unattributed | — | — | — |
| TL-2026-0528 | 2026-05-18 | @deadcode09284814/axios-util | — | — | ✗ | @deadcode09284814 | Unattributed | — | — | — |
| TL-2026-0528 | 2026-05-18 | axois-utils | — | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0528 | 2026-05-18 | chalk-tempalte | — | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0528 | 2026-05-18 | color-style-utils | — | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0530 | 2026-05-19 | @antv/component | 2.2.11 | — | ✗ | @antv | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0530 | 2026-05-19 | @antv/g2 | 5.5.8 | — | ✗ | @antv | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0530 | 2026-05-19 | @antv/g6 | 5.2.1 | — | ✗ | @antv | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0530 | 2026-05-19 | @antv/mcp-server-chart | 0.10.10 | — | ✗ | @antv | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0530 | 2026-05-19 | @antv/util | 3.4.11 | — | ✗ | @antv | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0530 | 2026-05-19 | nrwl.angular-console | 18.95.0 | 18.94.x or post-incident >= 18.96.0 | ✓ | Nrwl | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0547 | 2026-05-21 | @tanstack/react-router | 1.169.5, 1.169.8 | 1.169.9+ | ✓ | TanStack | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0547 | 2026-05-21 | @tanstack/router-core | 1.169.5, 1.169.8 | 1.169.9+ | ✓ | TanStack | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0547 | 2026-05-21 | @tanstack/solid-router | 1.169.5, 1.169.8 | 1.169.9+ | ✓ | TanStack | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0547 | 2026-05-21 | @tanstack/vue-router | 1.169.5, 1.169.8 | 1.169.9+ | ✓ | TanStack | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0556 | 2026-05-21 | @tiledesk/tiledesk-server | 2.18.6, 2.18.7, 2.18.8, 2.18.9, 2.18.10, 2.18.11, 2.18.12 | — | ✗ | Tiledesk | Unattributed | — | — | — |
| TL-2026-0559 | 2026-05-22 | pinno-loggers | all published versions | — | ✗ | npm registry (OpenJS / GitHub) | Contagious Interview | North Korea (DPRK) | Financial theft & espionage | 11 |
| TL-2026-0559 | 2026-05-22 | pretty-logger-utils | all published versions | — | ✗ | npm registry (OpenJS / GitHub) | Contagious Interview | North Korea (DPRK) | Financial theft & espionage | 11 |
| TL-2026-0559 | 2026-05-22 | terminal-logger-utils | all published versions | — | ✗ | npm registry (OpenJS / GitHub) | Contagious Interview | North Korea (DPRK) | Financial theft & espionage | 11 |
| TL-2026-0559 | 2026-05-22 | ts-logger-pack | all published versions | — | ✗ | npm registry (OpenJS / GitHub) | Contagious Interview | North Korea (DPRK) | Financial theft & espionage | 11 |
| TL-2026-0568 | 2026-05-22 | art-template | 4.13.3, 4.13.5, 4.13.6, 4.13.4 | 4.13.2 (last known clean release, 2018-11-13) | ✓ | aui (original) / daughtrymom + npmpacketmaintainmember7 (npm hijacker) | Unattributed | — | — | — |
| TL-2026-0576 | 2026-05-24 | crates.io | 6 Sui/Move-themed crates | crates yanked | ✓ | Rust Foundation | TrapDoor | Unknown (cybercrime) | Financial (crypto wallet theft) | 1 |
| TL-2026-0608 | 2026-05-27 | forge-jsx | 1.0.0 through 1.0.66 (66 versions, all malicious) | Replaced by npm security placeholder on 2026-05-04 | ✓ | npm Registry | Unattributed | — | — | — |
| TL-2026-0608 | 2026-05-27 | forge-jsxy | 1.0.66 through 1.0.91 (22 versions, all malicious) | Package fully malicious — remove and report; no fixed version exists | ✓ | npm Registry | Unattributed | — | — | — |
| TL-2026-0621 | 2026-05-28 | mouse5212-super-formatter | 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4 | unpublished from npm 2026-05-27 | ✓ | npm registry (mouse5212-super-formatter maintainer) | Unattributed | — | — | — |
| TL-2026-0623 | 2026-05-29 | @vpmdhaj/devops-tools | 1.0.7267 | — | ✗ | @vpmdhaj | Unattributed | — | — | — |
| TL-2026-0623 | 2026-05-29 | @vpmdhaj/elastic-helper | 1.0.7269 | — | ✗ | @vpmdhaj | Unattributed | — | — | — |
| TL-2026-0623 | 2026-05-29 | @vpmdhaj/opensearch-setup | 1.0.7267 | — | ✗ | @vpmdhaj | Unattributed | — | — | — |
| TL-2026-0623 | 2026-05-29 | @vpmdhaj/search-setup | 1.0.7268 | — | ✗ | @vpmdhaj | Unattributed | — | — | — |
| TL-2026-0623 | 2026-05-29 | app-config-utility | 1.0.9300 | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0623 | 2026-05-29 | elastic-opensearch-helper | 1.0.9108 | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0623 | 2026-05-29 | env-config-manager | 2.1.9201 | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0623 | 2026-05-29 | opensearch-config-utility | 1.0.9106 | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0623 | 2026-05-29 | opensearch-security-scanner | 1.0.10 | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0623 | 2026-05-29 | opensearch-setup | 1.0.9103 | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0623 | 2026-05-29 | opensearch-setup-tool | 1.0.9108 | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0623 | 2026-05-29 | search-cluster-setup | 1.0.9104 | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0623 | 2026-05-29 | search-engine-setup | 1.0.9108 | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0623 | 2026-05-29 | vpmdhaj-opensearch-setup | 1.0.9102 | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0633 | 2026-05-29 | @capibar.chat/ui-kit | — | — | ✗ | @capibar.chat | Unattributed | — | — | — |
| TL-2026-0633 | 2026-05-29 | @cloudplatform-single-spa/logaas | — | — | ✗ | @cloudplatform-single-spa | Unattributed | — | — | — |
| TL-2026-0633 | 2026-05-29 | @sber-ecom-core/sberpay-widget | — | — | ✗ | @sber-ecom-core | Unattributed | — | — | — |
| TL-2026-0633 | 2026-05-29 | @wb-track/shared-front | — | — | ✗ | @wb-track | Unattributed | — | — | — |
| TL-2026-0641 | 2026-06-01 | codexui-android | 0.1.82, >=0.1.82 (malicious dist-cli build) | clean GitHub source friuns2/codex-mobile (no malicious code) | ✓ | friuns2 (npm) | Unattributed | — | — | — |
| TL-2026-0643 | 2026-06-01 | @redhat-cloud-services/chrome | 2.3.1 | — | ✗ | @redhat-cloud-services | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0643 | 2026-06-01 | @redhat-cloud-services/frontend-components | 7.7.2 | — | ✗ | @redhat-cloud-services | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0643 | 2026-06-01 | @redhat-cloud-services/host-inventory-client | 5.0.3 | — | ✗ | @redhat-cloud-services | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0643 | 2026-06-01 | @redhat-cloud-services/rbac-client | 9.0.3 | — | ✗ | @redhat-cloud-services | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-0726 | 2026-06-09 | buffer-util-extend | — | — | ✗ | — | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0726 | 2026-06-09 | buffer-utilities | 1.0.0 | — | ✗ | — | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0726 | 2026-06-09 | chai-as-patch | — | — | ✗ | — | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0726 | 2026-06-09 | chai-beta | — | — | ✗ | — | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0726 | 2026-06-09 | express-denv | — | — | ✗ | — | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0726 | 2026-06-09 | jwt-path | — | — | ✗ | — | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0726 | 2026-06-09 | midcore | — | — | ✗ | — | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0726 | 2026-06-09 | midcorp | — | — | ✗ | — | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0726 | 2026-06-09 | node-background-invoker-v2 | 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6 | — | ✗ | — | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0726 | 2026-06-09 | react-next-dom | — | — | ✗ | — | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0726 | 2026-06-09 | webpack-patch | — | — | ✗ | — | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0733 | 2026-06-09 | @asyncapi/specs | — | — | ✓ | @asyncapi | Shai-Hulud operators | Unknown (cybercrime) | Financial (credential/token theft worm) | 4 |
| TL-2026-0733 | 2026-06-09 | @ctrl/tinycolor | — | — | ✓ | @ctrl | Shai-Hulud operators | Unknown (cybercrime) | Financial (credential/token theft worm) | 4 |
| TL-2026-0733 | 2026-06-09 | @postman/tunnel-agent | — | — | ✓ | @postman | Shai-Hulud operators | Unknown (cybercrime) | Financial (credential/token theft worm) | 4 |
| TL-2026-0782 | 2026-06-12 | atomic-lockfile | 1.4.2 | Package removed; do not install | ✓ | npm Registry | Unattributed | — | — | — |
| TL-2026-0782 | 2026-06-12 | js-digest | all published | Package removed; do not install | ✓ | npm / bun Registry | Unattributed | — | — | — |
| TL-2026-0788 | 2026-06-14 | atomic-lockfile | 1.4.2 | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0788 | 2026-06-14 | js-digest | — | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0813 | 2026-06-15 | bjs-lint-builders | — | — | ✗ | — | Contagious Interview | North Korea (DPRK) | Financial theft & espionage | 11 |
| TL-2026-0813 | 2026-06-15 | nextjs-https-supertest | — | — | ✗ | — | Contagious Interview | North Korea (DPRK) | Financial theft & espionage | 11 |
| TL-2026-0813 | 2026-06-15 | nicegui | 0.1.4 | — | ✗ | — | Contagious Interview | North Korea (DPRK) | Financial theft & espionage | 11 |
| TL-2026-0813 | 2026-06-15 | node-env-resolve | — | — | ✗ | — | Contagious Interview | North Korea (DPRK) | Financial theft & espionage | 11 |
| TL-2026-0813 | 2026-06-15 | period-newline | 0.1.0 | — | ✗ | — | Contagious Interview | North Korea (DPRK) | Financial theft & espionage | 11 |
| TL-2026-0813 | 2026-06-15 | redeem-onchain-sdk | 1.0.7 | — | ✗ | — | Contagious Interview | North Korea (DPRK) | Financial theft & espionage | 11 |
| TL-2026-0813 | 2026-06-15 | sleek-pretty | — | — | ✗ | — | Contagious Interview | North Korea (DPRK) | Financial theft & espionage | 11 |
| TL-2026-0813 | 2026-06-15 | vite-meta-plugin | — | — | ✗ | — | Contagious Interview | North Korea (DPRK) | Financial theft & espionage | 11 |
| TL-2026-0829 | 2026-06-16 | pipelines | any host installing the package | — | ✗ | Developer / CI-CD environments | Shai-Hulud operators | Unknown (cybercrime) | Financial (credential/token theft worm) | 4 |
| TL-2026-0829 | 2026-06-16 | shai_hulululud | 1.0.48596 | — | ✗ | npm (OpenJS / npm Registry) | Shai-Hulud operators | Unknown (cybercrime) | Financial (credential/token theft worm) | 4 |
| TL-2026-0834 | 2026-06-17 | @mastra/core | 1.42.1 (and all @mastra/core versions published 2026-06-17 without SLSA provenance), 1.42.1 | clean versions republished with valid provenance after 2026-06-17 | ✓ | Mastra | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0834 | 2026-06-17 | @mastra/memory | 1.20.4 | post-incident clean republish | ✓ | Mastra | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0834 | 2026-06-17 | @mastra/schema-compat | 1.2.12 | post-incident clean republish | ✓ | Mastra | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0834 | 2026-06-17 | @mastra/server | 2.1.1 | post-incident clean republish | ✓ | Mastra | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0834 | 2026-06-17 | easy-day-js | 1.11.22 (weaponized), 1.11.21 (clean decoy, attacker-controlled), 1.11.21, 1.11.22 | remove entirely; not a legitimate package | ✓ | easy-day-js (typosquat, attacker-controlled) | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0834 | 2026-06-17 | mastra | 1.13.1 | post-incident clean republish | ✓ | Mastra | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0836 | 2026-06-17 | @mastra/core | — | — | ✗ | @mastra | Unattributed | — | — | — |
| TL-2026-0836 | 2026-06-17 | easy-day-js | 1.11.21, 1.11.22 | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0845 | 2026-06-17 | autoadv | 1.0.0 | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0845 | 2026-06-17 | node-dlls | 1.0.0 | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0845 | 2026-06-17 | ro.dll | 1.0.0 | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0845 | 2026-06-17 | rolimons-api | 1.1.0, 1.1.2 | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0898 | 2026-06-22 | easy-day-js | 1.11.22 (weaponized), 1.11.21 (clean decoy bait), 1.11.21, 1.11.22 | — | ✗ | npm (transitive dependency) | APT38 | North Korea (DPRK) | Financial theft | 9 |
| TL-2026-0910 | 2026-06-23 | aes-decode-runner-pro | — | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0910 | 2026-06-23 | postcss-minify-selector | — | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0910 | 2026-06-23 | postcss-minify-selector-parser | — | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-0977 | 2026-06-17 | @mastra/core | All versions republished 2026-06-17 during 27-minute compromise window | Versions released after Mastra maintainers revoked compromised package versions | ✓ | Mastra | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0977 | 2026-06-17 | easy-day-js | All versions of the malicious easy-day-js package | Package removed from registry; all versions yanked | ✓ | NPM Registry | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-0987 | 2026-06-28 | fetch-page-assets | 1.2.9 | — | ✗ | npm (JavaScript Package Registry) | Unattributed | — | — | — |
| TL-2026-0987 | 2026-06-28 | html-to-gutenberg | 4.2.11 | — | ✗ | npm (JavaScript Package Registry) | Unattributed | — | — | — |
| TL-2026-1008 | 2026-06-30 | python-wolfssl | — | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-1030 | 2026-07-01 | fetch-page-assets | — | — | ✗ | — | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-1030 | 2026-07-01 | html-to-gutenberg | — | — | ✗ | — | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-1030 | 2026-07-01 | quirky-token | all published versions (XRAY-1003392) | package removed from npm registry | ✓ | npm | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-1030 | 2026-07-01 | react-icon-svgs | all published versions (XRAY-1011624) | package removed from npm registry | ✓ | npm | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-1030 | 2026-07-01 | rollup-packages-polyfill-core | all published versions (XRAY-1008625) | package removed from npm registry | ✓ | npm | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-1030 | 2026-07-01 | rollup-plugin-polyfill-connect | all published versions (XRAY-973019) | package removed from npm registry | ✓ | npm | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-1030 | 2026-07-01 | rollup-runtime-polyfill-core | all published versions (XRAY-1008531) | package removed from npm registry | ✓ | npm | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-1030 | 2026-07-01 | swift-parse-stream | all published versions (XRAY-1005725) | package removed from npm registry | ✓ | npm | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-1055 | 2026-07-01 | tailwind-animationbased | all published versions | not confirmed | ✓ | npm | PolinRider | North Korea (DPRK) | Cryptocurrency theft | 4 |
| TL-2026-1055 | 2026-07-01 | tailwind-autoanimation | 2.3.6 | removed from registry | ✓ | npm | PolinRider | North Korea (DPRK) | Cryptocurrency theft | 4 |
| TL-2026-1055 | 2026-07-01 | tailwind-mainanimation | 2.3.3 | 0.0.1 security placeholder | ✓ | npm | PolinRider | North Korea (DPRK) | Cryptocurrency theft | 4 |
| TL-2026-1055 | 2026-07-01 | tailwindcss-animate-style | 1.2.5 | not confirmed | ✓ | npm | PolinRider | North Korea (DPRK) | Cryptocurrency theft | 4 |
| TL-2026-1055 | 2026-07-01 | tailwindcss-style-animate | 1.1.6 | removed from registry | ✓ | npm | PolinRider | North Korea (DPRK) | Cryptocurrency theft | 4 |
| TL-2026-1055 | 2026-07-01 | tailwindcss-style-modify | 0.8.3 | not confirmed | ✓ | npm | PolinRider | North Korea (DPRK) | Cryptocurrency theft | 4 |
| TL-2026-1055 | 2026-07-01 | tailwindcss-typography-style | 0.8.2 | not confirmed | ✓ | npm | PolinRider | North Korea (DPRK) | Cryptocurrency theft | 4 |
| TL-2026-1120 | 2026-07-01 | tailwind-autoanimation | — | — | ✗ | — | Contagious Interview | North Korea (DPRK) | Financial theft & espionage | 11 |
| TL-2026-1120 | 2026-07-01 | tailwind-mainanimation | — | — | ✗ | — | Contagious Interview | North Korea (DPRK) | Financial theft & espionage | 11 |
| TL-2026-1120 | 2026-07-01 | tailwindcss-style-animate | — | — | ✗ | — | Contagious Interview | North Korea (DPRK) | Financial theft & espionage | 11 |
| TL-2026-1143 | 2026-06-21 | @aifabrix/miso-client | malicious versions | N/A | ✓ | npm | PolinRider | North Korea (DPRK) | Cryptocurrency theft | 4 |
| TL-2026-1143 | 2026-06-21 | @iflow-mcp/watercrawl-watercrawl-mcp | malicious versions | N/A | ✓ | npm | PolinRider | North Korea (DPRK) | Cryptocurrency theft | 4 |
| TL-2026-1143 | 2026-06-21 | @usebioerhold8733/s-format | 4 incrementally-staged malicious versions published within a 48-hour window | N/A | ✓ | npm | PolinRider | North Korea (DPRK) | Cryptocurrency theft | 4 |
| TL-2026-1143 | 2026-06-21 | tailwind-autoanimation | all published malicious versions injecting payload into src/index.js | N/A | ✓ | npm | PolinRider | North Korea (DPRK) | Cryptocurrency theft | 4 |
| TL-2026-1143 | 2026-06-21 | tailwind-mainanimation | all published malicious versions | removed by npm | ✓ | npm | PolinRider | North Korea (DPRK) | Cryptocurrency theft | 4 |
| TL-2026-1143 | 2026-06-21 | tailwindcss-style-animate | 1.1.6 and re-published malicious versions | package removed/scrubbed from registry | ✓ | npm | PolinRider | North Korea (DPRK) | Cryptocurrency theft | 4 |
| TL-2026-1149 | 2026-07-08 | @injectivelabs/sdk-ts | 1.20.21 | 1.20.23 | ✓ | Injective Labs | Unattributed | — | — | — |
| TL-2026-1153 | 2026-07-09 | @injectivelabs/exceptions | 1.20.21 | 1.20.23 | ✓ | InjectiveLabs | Unattributed | — | — | — |
| TL-2026-1153 | 2026-07-09 | @injectivelabs/networks | 1.20.21 | 1.20.23 | ✓ | InjectiveLabs | Unattributed | — | — | — |
| TL-2026-1153 | 2026-07-09 | @injectivelabs/sdk-ts | 1.20.21 | 1.20.23 | ✓ | InjectiveLabs | Unattributed | — | — | — |
| TL-2026-1153 | 2026-07-09 | @injectivelabs/ts-types | 1.20.21 | 1.20.23 | ✓ | InjectiveLabs | Unattributed | — | — | — |
| TL-2026-1153 | 2026-07-09 | @injectivelabs/utils | 1.20.21 | 1.20.23 | ✓ | InjectiveLabs | Unattributed | — | — | — |
| TL-2026-1153 | 2026-07-09 | @injectivelabs/wallet-base | 1.20.21 | 1.20.23 | ✓ | InjectiveLabs | Unattributed | — | — | — |
| TL-2026-1153 | 2026-07-09 | @injectivelabs/wallet-core | 1.20.21 | 1.20.23 | ✓ | InjectiveLabs | Unattributed | — | — | — |
| TL-2026-1153 | 2026-07-09 | @injectivelabs/wallet-cosmos | 1.20.21 | 1.20.23 | ✓ | InjectiveLabs | Unattributed | — | — | — |
| TL-2026-1153 | 2026-07-09 | @injectivelabs/wallet-cosmos-strategy | 1.20.21 | 1.20.23 | ✓ | InjectiveLabs | Unattributed | — | — | — |
| TL-2026-1153 | 2026-07-09 | @injectivelabs/wallet-cosmostation | 1.20.21 | 1.20.23 | ✓ | InjectiveLabs | Unattributed | — | — | — |
| TL-2026-1153 | 2026-07-09 | @injectivelabs/wallet-evm | 1.20.21 | 1.20.23 | ✓ | InjectiveLabs | Unattributed | — | — | — |
| TL-2026-1153 | 2026-07-09 | @injectivelabs/wallet-ledger | 1.20.21 | 1.20.23 | ✓ | InjectiveLabs | Unattributed | — | — | — |
| TL-2026-1153 | 2026-07-09 | @injectivelabs/wallet-magic | 1.20.21 | 1.20.23 | ✓ | InjectiveLabs | Unattributed | — | — | — |
| TL-2026-1153 | 2026-07-09 | @injectivelabs/wallet-private-key | 1.20.21 | 1.20.23 | ✓ | InjectiveLabs | Unattributed | — | — | — |
| TL-2026-1153 | 2026-07-09 | @injectivelabs/wallet-strategy | 1.20.21 | 1.20.23 | ✓ | InjectiveLabs | Unattributed | — | — | — |
| TL-2026-1153 | 2026-07-09 | @injectivelabs/wallet-trezor | 1.20.21 | 1.20.23 | ✓ | InjectiveLabs | Unattributed | — | — | — |
| TL-2026-1153 | 2026-07-09 | @injectivelabs/wallet-turnkey | 1.20.21 | 1.20.23 | ✓ | InjectiveLabs | Unattributed | — | — | — |
| TL-2026-1153 | 2026-07-09 | @injectivelabs/wallet-wallet-connect | 1.20.21 | 1.20.23 | ✓ | InjectiveLabs | Unattributed | — | — | — |
| TL-2026-1164 | 2026-07-10 | jscodeshift | — | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-1164 | 2026-07-10 | react-codemod | — | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-1164 | 2026-07-10 | react-codeshift | — | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-1215 | 2026-07-11 | safe-validate | 1.0.4 | — | ✗ | npm (deepthought26 publisher account) | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-1215 | 2026-07-11 | tailwind-color-shades | 1.0.2 | — | ✗ | npm (deepthought26 publisher account) | Lazarus Group | North Korea (DPRK) | Financial theft & espionage | 18 |
| TL-2026-1233 | 2026-07-11 | jscrambler | 8.14.0, 8.13.0 | 8.13.0 (last known-clean; roll back pending official remediation) | ✓ | Jscrambler | Unattributed | — | — | — |
| TL-2026-1234 | 2026-06-04 | @vapi-ai/server-sdk | 0.11.1, 0.11.2, 1.2.1, 1.2.2 | removed/unpublished versions post-2026-06-04 | ✓ | npm (open source) | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-1234 | 2026-06-04 | ai-sdk-ollama | 0.13.1, 1.1.1, 2.2.1, 3.8.5 | removed/unpublished versions post-2026-06-04 | ✓ | npm (open source) | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-1234 | 2026-06-04 | eslint-plugin-awaitly | — | — | ✗ | — | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-1234 | 2026-06-04 | executable-stories-cypress | — | — | ✗ | — | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-1234 | 2026-06-04 | node-env-resolver-aws | — | — | ✗ | — | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-1234 | 2026-06-04 | wrangler-deploy | — | — | ✗ | — | TeamPCP | Unknown (cybercrime) | Financial (self-propagating worm) | 40 |
| TL-2026-1238 | 2026-07-11 | jscrambler | 8.14.0 | 8.15.0, 8.13.0 (revert) | ✓ | jscrambler | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | hexo-deployer-wrangler | 1.0.4 | n/a - malicious release | ✓ | llxlr (npm account) | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | hexo-shoka-swiper | 0.1.10 | n/a - malicious release | ✓ | llxlr (npm account) | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | leo-auth | 4.0.6 | revert to last known-clean version prior to 2026-06-24 | ✓ | LeoPlatform/RStreams | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | leo-aws | 2.0.4 | pre-2026-06-24 release | ✓ | LeoPlatform/RStreams | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | leo-cache | 1.0.2 | pre-2026-06-24 release | ✓ | LeoPlatform/RStreams | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | leo-cdk-lib | 0.0.2 | pre-2026-06-24 release | ✓ | LeoPlatform/RStreams | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | leo-cli | 3.0.3 | pre-2026-06-24 release | ✓ | LeoPlatform/RStreams | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | leo-config | 1.1.1 | pre-2026-06-24 release | ✓ | LeoPlatform/RStreams | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | leo-connector-elasticsearch | 2.0.6 | pre-2026-06-24 release | ✓ | LeoPlatform/RStreams | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | leo-connector-mongo | 3.0.8 | pre-2026-06-24 release | ✓ | LeoPlatform/RStreams | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | leo-connector-mysql | 3.0.3 | pre-2026-06-24 release | ✓ | LeoPlatform/RStreams | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | leo-connector-oracle | 2.0.1 | pre-2026-06-24 release | ✓ | LeoPlatform/RStreams | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | leo-connector-redshift | 3.0.6 | pre-2026-06-24 release | ✓ | LeoPlatform/RStreams | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | leo-cron | 2.0.2 | pre-2026-06-24 release | ✓ | LeoPlatform/RStreams | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | leo-logger | 1.0.8 | pre-2026-06-24 release | ✓ | LeoPlatform/RStreams | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | leo-sdk | 6.0.19 | pre-2026-06-24 release | ✓ | LeoPlatform/RStreams | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | leo-streams | 2.0.1 | pre-2026-06-24 release | ✓ | LeoPlatform/RStreams | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | prism-silq | 1.0.1 | n/a - malicious release | ✓ | llxlr (npm account) | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | rstreams-metrics | 2.0.2 | pre-2026-06-24 release | ✓ | LeoPlatform/RStreams | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | rstreams-shard-util | 1.0.1 | pre-2026-06-24 release | ✓ | LeoPlatform/RStreams | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | serverless-convention | 2.0.4 | pre-2026-06-24 release | ✓ | LeoPlatform/RStreams | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | serverless-leo | 3.0.14 | pre-2026-06-24 release | ✓ | LeoPlatform/RStreams | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | solo-nav | 1.0.1 | n/a - malicious release | ✓ | llxlr (npm account) | Unattributed | — | — | — |
| TL-2026-1242 | 2026-06-26 | verana-blockchain | v0.10.1-dev.20 | revert to clean prior commit/tag | ✓ | Verana Labs | Unattributed | — | — | — |
| TL-2026-1293 | 2026-07-14 | @asyncapi/generator | 3.3.1 | — | ✗ | AsyncAPI Initiative | Miasma operators | Unknown (cybercrime) | Financial (self-propagating worm) | 3 |
| TL-2026-1293 | 2026-07-14 | @asyncapi/generator-components | 0.7.1 | — | ✗ | AsyncAPI Initiative | Miasma operators | Unknown (cybercrime) | Financial (self-propagating worm) | 3 |
| TL-2026-1293 | 2026-07-14 | @asyncapi/generator-helpers | 1.1.1 | — | ✗ | AsyncAPI Initiative | Miasma operators | Unknown (cybercrime) | Financial (self-propagating worm) | 3 |
| TL-2026-1293 | 2026-07-14 | @vapi-ai/server-sdk | 0.11.1, 0.11.2, 1.2.1, 1.2.2 | — | ✗ | Vapi | Miasma operators | Unknown (cybercrime) | Financial (self-propagating worm) | 3 |
| TL-2026-1296 | 2026-07-14 | changiairportpromax | — | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-1296 | 2026-07-14 | charlie-kirk | — | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-1296 | 2026-07-14 | ilovefemboys | — | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-1296 | 2026-07-14 | miguelphonk | — | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-1296 | 2026-07-14 | ratelimitsucks | — | — | ✗ | — | Unattributed | — | — | — |
| TL-2026-1299 | 2026-07-14 | @asyncapi/generator | 3.3.1 | unpublished/removed by npm and maintainers post-disclosure | ✓ | AsyncAPI Initiative | Unattributed | — | — | — |
| TL-2026-1299 | 2026-07-14 | @asyncapi/generator-components | 0.7.1 | unpublished/removed by npm and maintainers post-disclosure | ✓ | AsyncAPI Initiative | Unattributed | — | — | — |
| TL-2026-1299 | 2026-07-14 | @asyncapi/generator-helpers | 1.1.1 | unpublished/removed by npm and maintainers post-disclosure | ✓ | AsyncAPI Initiative | Unattributed | — | — | — |
| TL-2026-1299 | 2026-07-14 | @asyncapi/specs | 6.11.2, 6.11.2-alpha.1 | unpublished/removed by npm and maintainers post-disclosure | ✓ | AsyncAPI Initiative | Unattributed | — | — | — |
| TL-2026-1320 | 2026-07-14 | @asyncapi/generator | 3.3.1 | 3.3.0 (downgrade/pin) | ✓ | AsyncAPI Initiative | Unattributed | — | — | — |
| TL-2026-1320 | 2026-07-14 | @asyncapi/generator-components | 0.7.1 | 0.7.0 (downgrade/pin) | ✓ | AsyncAPI Initiative | Unattributed | — | — | — |
| TL-2026-1320 | 2026-07-14 | @asyncapi/generator-helpers | 1.1.1 | 1.1.0 (downgrade/pin) | ✓ | AsyncAPI Initiative | Unattributed | — | — | — |
| TL-2026-1320 | 2026-07-14 | @asyncapi/specs | 6.11.2, 6.11.2-alpha.1 | 6.11.1 (downgrade/pin) | ✓ | AsyncAPI Initiative | Unattributed | — | — | — |
| TL-2026-1360 | 2026-07-15 | @asyncapi/generator | 3.3.1 | 3.3.0 (rollback) | ✓ | AsyncAPI Initiative | Unattributed | — | — | — |
| TL-2026-1360 | 2026-07-15 | @asyncapi/generator-components | 0.7.1 | 1.0.0 | ✓ | AsyncAPI Initiative | Unattributed | — | — | — |
| TL-2026-1360 | 2026-07-15 | @asyncapi/generator-helpers | 1.1.1 | 1.1.0 (rollback) | ✓ | AsyncAPI Initiative | Unattributed | — | — | — |
| TL-2026-1360 | 2026-07-15 | @asyncapi/specs | 6.11.2, 6.11.2-alpha.1 | 6.11.1 (rollback) | ✓ | AsyncAPI Initiative | Unattributed | — | — | — |
| TL-2026-1379 | 2026-07-15 | jscrambler | 8.14.0, 8.16.0, 8.17.0, 8.18.0, 8.20.0 | 8.22.0 | ✓ | Jscrambler | Unattributed | — | — | — |
| TL-2026-1381 | 2026-07-15 | @injectivelabs/exceptions | 1.20.21 | 1.20.23 or later | ✓ | Injective Labs | Unattributed | — | — | — |
| TL-2026-1381 | 2026-07-15 | @injectivelabs/networks | 1.20.21 | 1.20.23 or later | ✓ | Injective Labs | Unattributed | — | — | — |
| TL-2026-1381 | 2026-07-15 | @injectivelabs/sdk-ts | 1.20.21 | 1.20.23 | ✓ | Injective Labs | Unattributed | — | — | — |
| TL-2026-1381 | 2026-07-15 | @injectivelabs/ts-types | 1.20.21 | 1.20.23 or later | ✓ | Injective Labs | Unattributed | — | — | — |
| TL-2026-1381 | 2026-07-15 | @injectivelabs/utils | 1.20.21 | 1.20.23 or later, or unpin from malicious version | ✓ | Injective Labs | Unattributed | — | — | — |
| TL-2026-1381 | 2026-07-15 | @injectivelabs/wallet-base | 1.20.21 | 1.20.23 or later | ✓ | Injective Labs | Unattributed | — | — | — |
| TL-2026-1381 | 2026-07-15 | @injectivelabs/wallet-core | 1.20.21 | 1.20.23 or later | ✓ | Injective Labs | Unattributed | — | — | — |
| TL-2026-1381 | 2026-07-15 | @injectivelabs/wallet-cosmos | 1.20.21 | 1.20.23 or later | ✓ | Injective Labs | Unattributed | — | — | — |
| TL-2026-1381 | 2026-07-15 | @injectivelabs/wallet-cosmos-strategy | 1.20.21 | 1.20.23 or later | ✓ | Injective Labs | Unattributed | — | — | — |
| TL-2026-1381 | 2026-07-15 | @injectivelabs/wallet-cosmostation | 1.20.21 | 1.20.23 or later | ✓ | Injective Labs | Unattributed | — | — | — |
| TL-2026-1381 | 2026-07-15 | @injectivelabs/wallet-evm | 1.20.21 | 1.20.23 or later | ✓ | Injective Labs | Unattributed | — | — | — |
| TL-2026-1381 | 2026-07-15 | @injectivelabs/wallet-ledger | 1.20.21 | 1.20.23 or later | ✓ | Injective Labs | Unattributed | — | — | — |
| TL-2026-1381 | 2026-07-15 | @injectivelabs/wallet-magic | 1.20.21 | 1.20.23 or later | ✓ | Injective Labs | Unattributed | — | — | — |
| TL-2026-1381 | 2026-07-15 | @injectivelabs/wallet-private-key | 1.20.21 | 1.20.23 or later | ✓ | Injective Labs | Unattributed | — | — | — |
| TL-2026-1381 | 2026-07-15 | @injectivelabs/wallet-strategy | 1.20.21 | 1.20.23 or later | ✓ | Injective Labs | Unattributed | — | — | — |
| TL-2026-1381 | 2026-07-15 | @injectivelabs/wallet-trezor | 1.20.21 | 1.20.23 or later | ✓ | Injective Labs | Unattributed | — | — | — |
| TL-2026-1381 | 2026-07-15 | @injectivelabs/wallet-turnkey | 1.20.21 | 1.20.23 or later | ✓ | Injective Labs | Unattributed | — | — | — |
| TL-2026-1381 | 2026-07-15 | @injectivelabs/wallet-wallet-connect | 1.20.21 | 1.20.23 or later | ✓ | Injective Labs | Unattributed | — | — | — |
| TL-2026-1387 | 2026-07-15 | @asyncapi/generator | 3.3.1 | 3.3.0 | ✓ | AsyncAPI Initiative | Unattributed | — | — | — |
| TL-2026-1387 | 2026-07-15 | @asyncapi/generator-components | 0.7.1 | 1.0.0 | ✓ | AsyncAPI Initiative | Unattributed | — | — | — |
| TL-2026-1387 | 2026-07-15 | @asyncapi/generator-helpers | 1.1.1 | 1.1.0 | ✓ | AsyncAPI Initiative | Unattributed | — | — | — |
| TL-2026-1387 | 2026-07-15 | @asyncapi/specs | 6.11.2-alpha.1, 6.11.2 | 6.11.1 or earlier | ✓ | AsyncAPI Initiative | Unattributed | — | — | — |
Sorted by threat ID (Threadlinqs TL number). Click any column header to re-sort; type to filter. Every TL number links to the full enriched threat record; every package links to its npm registry page; every attributed actor links to its actor profile. Vulnerable/fixed versions mirror each threat's // affected section. “Actor threats” is the number of threats attributed to that actor across the Threadlinqs corpus.
How to protect against npm supply chain attacks: a checklist
Prioritized for a security team working from the top down:
- Now: Cross-reference the master list against your lockfiles and CI caches. Any match means assume credential exposure, not just a bad dependency.
- Now: Rotate every secret reachable from a build runner — cloud keys,
NPM_TOKEN,GITHUB_TOKEN, Vault tokens, kubeconfigs. The worms harvest at install time, so exposure predates detection. - This week: Audit
pull_request_targetworkflows. Remove secret access from any workflow that checks out untrusted PR code; this single primitive drove the highest-impact compromises. - This week: Set
--ignore-scriptsin CI and disable node-gyp for pure-JS dependency trees; a straybinding.gypshould never execute. - This week: Inventory AI-agent configs (
~/.claude.json,.cursor/,.continue/,.windsurf/) as sensitive credential stores and alert on modification. - Ongoing: Enforce lockfile pinning with integrity hashes, require
npm audit signatures, and move all publish flows to short-lived OIDC with legacy tokens revoked. - Ongoing: Revoke dormant maintainer and contributor access quarterly. Several compromises rode accounts that had not published in months.
- Ongoing: Egress-filter and log DNS TXT volume, non-standard outbound ports, and traffic to paste sites and blockchain RPC endpoints from build hosts.
Frequently asked questions
What is an npm supply chain attack?
An npm supply chain attack compromises a trusted package in the npm registry — by stealing a maintainer's publish token, hijacking a dormant account, or poisoning the CI/CD pipeline that publishes it — so that every project installing the package also pulls attacker code. Because a single popular package can be a dependency of millions of projects, one compromise cascades across the ecosystem.
How many npm packages were compromised in 2026?
Between February 1 and July 15, 2026, Threadlinqs Intelligence documented 78 distinct npm supply chain attacks involving 218 unique malicious packages across 308 documented package records. The full, sortable list — with vulnerable and fixed versions and the attributed threat actor — is in the master table on this page.
What is the Shai-Hulud npm worm?
Shai-Hulud is a family of self-replicating npm worms — including Mini Shai-Hulud, Miasma, Hades, and the compiled-Rust IronWorm — that harvest cloud and CI credentials at install time and then auto-republish through the maintainer accounts they just stole from. It is the first true worm behavior in the npm ecosystem, turning one compromise into self-propagating malware. Threadlinqs links the lineage to a crew tracked as TeamPCP, present in 40 of the 78 documented attacks.
Who is behind the 2026 npm supply chain attacks?
Attribution splits two ways. North Korea (DPRK) accounts for 23 of the 78 attacks (56% of those with a named actor), spread across the UNC1069/Sapphire Sleet, APT38, Lazarus Group, Contagious Interview, WageMole, and PolinRider clusters, motivated by cryptocurrency and credential theft. The other pole is financially motivated crimeware led by TeamPCP and its self-replicating worm family.
What is a binding.gyp "Phantom Gyp" attack?
Phantom Gyp is an install-time execution technique that avoids the obvious postinstall hook. An attacker drops a small binding.gyp file into a pure-JavaScript package; npm then invokes node-gyp during install, and node-gyp's command-substitution syntax executes attacker code without any lifecycle script being declared. The Miasma worm used a 157-byte binding.gyp to trojanize dozens of packages across hundreds of versions.
What is slopsquatting?
Slopsquatting (also called HalluSquatting) is a name-based attack that weaponizes AI: attackers pre-register the plausible-but-nonexistent package names that large language models hallucinate, so that when an AI coding assistant confidently suggests one of those names, the developer installs attacker-controlled code. It is typosquatting adapted to the era of AI-generated dependency suggestions.
How do I protect against npm supply chain attacks?
Enforce package provenance (npm audit signatures and SLSA), set --ignore-scripts by default in CI, pin exact versions with integrity hashes in committed lockfiles, scope publish tokens narrowly and prefer short-lived OIDC over legacy tokens, revoke dormant maintainer access, and adopt the npm 12 defaults that disable lifecycle scripts, node-gyp, Git dependencies, and remote tarballs. The remediation checklist on this page prioritizes these for a security team.
Track this in real time
Threadlinqs Intelligence tracks npm supply chain compromises as they happen — every package, version, IOC, detection rule, and threat actor, enriched and cross-linked. This article is a snapshot; the platform is live and updated nightly.
Start a free 7-day trial of Purple — the full detection library, real-time IOC enrichment, MCP access, and the correlation engine. Create an account to begin; no card required to start the trial.
[ start_free_7_day_trial ]Sources and further reading
- Socket — Axios npm package compromised
- Endor Labs — Shai-Hulud: inside the Bitwarden CLI supply-chain attack
- Aikido — Mini Shai-Hulud has appeared
- Wiz — Miasma supply-chain attack targeting Red Hat npm packages
- Snyk — node-gyp compromise: self-propagating npm worm (binding.gyp)
- Socket — Mastra npm packages compromised
- Datadog Security Labs — @injectivelabs/sdk-ts backdoor
- Socket — AsyncAPI supply-chain attack
- Socket — jscrambler supply-chain attack
- Google Cloud / Mandiant — North Korea targets the Axios npm package
- Datadog Security Labs — node-ipc npm malware analysis
- The Hacker News — npm 12 disables install scripts by default
- The Hacker News — new HalluSquatting attack tricks AI coding assistants
- The Hacker News — cross-ecosystem PyPI/npm compromise wave
- Aikido — Red Hat npm packages compromised by credential-stealing worm
- Sonatype — Atomic Arch npm campaign adds malicious dependency
- The Hacker News — malicious npm package steals files from AI sandbox
- Wiz Threat DB — SANDWORM_MODE typosquatted npm packages hijack CI workflows
- Aikido — GlassWorm returns: Unicode attack across GitHub, npm, VS Code
- CISA — supply-chain compromise impacts the Axios npm package
- CISA — cybersecurity advisories
- Google Cloud / Mandiant — DPRK adopts EtherHiding (blockchain dead-drops)