Malicious Packages articles

Original research and analysis on malicious packages in open source registries โ€” attack techniques like typosquatting, plus detection and defense.

10 malicious npm versions

Mini Shai-Hulud hits openapi-react-query-codegen: 10 malicious npm versions

An npm supply chain attack published ten malicious versions

Read More
Mini Shai Hulud Hits keyv

Mini Shai-Hulud Hits keyv: Trojanized Release Exfiltrates CI Secrets via GitHub

Trojanized keyv@6.0.0 exfiltrates CI secrets through GitHub’s own API.

Read More
Featured image Rubygems attack 1000x650

RubyGems supply chain attack: malware used as a credential exfiltration dead drop

RubyGems supply chain attack: stolen credentials hidden in the registry.

Read More
@Mastra e1782464597195 1

Mastra npm Scope Takeover: 140+ Packages Compromised via easy-day-js Dropper

@Mastra npm: 140+ Packages Compromised

Read More
Shai Hulud Miasma e1782464912450 1

Miasma: Red Hat Cloud Services npm Packages Hit by a Mini Shai-Hulud-Style Campaign

npm packages in @redhat-cloud-services drop a multi-stage cloud credential stealer.

Read More
Blog Cover Threat news

Laravel-Lang Composer tag-rewrite Supply Chain Attack

Four Laravel-Lang Composer packages were poisoned via tag rewrite.

Read More
Mini Shai Hulud is Back 1

Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account

Mini Shai-Hulud strikes again: 323 npm packages compromised via @antv’s atool.

Read More
Mend securing RubyGems

Inside the RubyGems Supply Chain Attack: How Mend Defender Caught a Coordinated Flood Before It Spread

How Mend.io caught a coordinated RubyGems attack and what it teaches us.

Read More
Mini Shai Hulud is Back

Mini Shai-Hulud Is Back: 172 npm and PyPI Packages Compromised in Latest Wave

Shai-Hulud’s largest wave: 172 npm and PyPI packages compromised in 48 hours.

Read More
npm supply chain attack

PhantomRaven Wave 5: New Undocumented NPM Supply Chain Campaign Targets DeFi, Cloud, and AI Developers

33 malicious NPM packages target DeFi, cloud, and AI developer credentials.

Read More
Blog Cover Linux Kernel LPE

CVE-2026-31431 (Copy Fail): Linux Kernel LPE

New Linux ‘copy_fail’ LPE gives root on all major distros. Mitigate before patching.

Read More
Mini Shai Hulud

Shai-Hulud Strikes SAP: Supply Chain Worm Weaponized Claude Code to Compromise the CAP Framework

SAP CAP packages compromised via Claude Code in AI-assisted worm attack.

Read More
The Butlerian Jihad

The Butlerian Jihad: Compromised Bitwarden CLI Deploys npm Worm, Poisons AI Assistants, and Dumps GitHub Secrets

Mend.io tracks TeamPCP’s latest supply chain attack.

Read More
Blog cover Team PCP part 4 1

A Poisoned Xinference Package Targets AI Inference Servers

Three poisoned xinference releases on PyPI target AI infrastructure credentials.

Read More
Blog cover Poisoned Axios

Poisoned Axios: npm Account Takeover, 50 Million Downloads, and a RAT That Vanishes After Install

See how the attack works, what to look for, and how to remediate.

Read More
Blog cover TEAM PCP part 3

Famous Telnyx Pypi Package compromised by TeamPCP

See how the attack works, what to look for, and how to remediate.

Read More