Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/Malicious Packages
Malware & Supply-Chain Attacks

Malicious Packages

22 notable real-world software supply-chain attacks — typosquats, account compromises, protestware, dependency-confusion, and backdoors — each with its impact and a public advisory reference.

22 incidents

@solana/web3.js2024A social-engineering attack on a maintainer led to malicious versions that stole private keys and drained wallets. Account compromisenpmcriticalpolyfill.io (polyfill-service)2024After the polyfill.io domain changed hands, the CDN began injecting malware into scripts served to sites embedding it, redirecting mobile users to malicious sites. Account compromiseCDNhighxz / liblzma2024A hidden backdoor was planted over years by a trusted maintainer ('Jia Tan') in the xz-utils compression library, targeting OpenSSH sshd via liblzma to allow remote code execution. BackdoorLinuxcritical@ledgerhq/connect-kit2023A former employee's npm access was abused to publish a version injecting a crypto wallet-drainer into any dApp loading the library. Account compromisenpmcriticalPyTorch / discordpydebug & similar2023Info-stealer packages posing as debugging or utility libraries have repeatedly appeared on PyPI, harvesting tokens, environment variables, and browser data on install. Malicious packagePyPImediumweb3-essential / crypto typosquats2023A recurring campaign publishes typosquats of popular web3 and crypto libraries that exfiltrate wallet seed phrases and environment secrets on install. Typosquatnpmmediumcolors / faker2022The maintainer deliberately sabotaged colors.js and faker.js with an infinite loop that printed garbage, breaking any app that depended on them. Protestwarenpmhighctx2022An abandoned PyPI package (and the phpass Composer package) was taken over and republished to exfiltrate AWS credentials from environment variables. Account compromisePyPIhighnode-ipc2022The maintainer added code ('peacenotwar') that overwrote files with a heart emoji on machines geolocated to Russia and Belarus. Protestwarenpmcriticaltorchtriton (pytorch-nightly)2022A malicious PyPI package named torchtriton shadowed a PyTorch dependency (dependency confusion), exfiltrating system info, hostnames, and SSH keys. Dependency confusionPyPIhighcoa / rc2021Maintainer accounts were compromised and malicious versions of coa and rc published, running a credential-stealing script. Account compromisenpmcriticalcodecov bash-uploader2021Attackers modified Codecov's Bash uploader script to exfiltrate environment variables (secrets, tokens) from customers' CI pipelines. Account compromiseCI/CDhighua-parser-js2021The maintainer's npm account was hijacked and malicious versions published, installing a crypto-miner and a password-stealing trojan on Windows and Linux. Account compromisenpmcriticalfallguys2020A package impersonating a 'Fall Guys' API read local Discord leveldb files to steal Discord authentication tokens. Malicious packagenpmmediumbootstrap-sass2019A malicious version of bootstrap-sass was published containing a backdoor allowing remote code execution via a crafted cookie. Account compromiseRubyGemshighelectron-native-notify2019A seemingly benign package was published, then updated with a payload used in a chained attack against the Agama cryptocurrency wallet to steal funds. Malicious packagenpmhighjeIlyfish (typosquat of jellyfish)2019A typosquat replacing the 'l' in jellyfish with a capital 'I' stole SSH and GPG keys from developers who mistyped the name. TyposquatPyPIhighrest-client2019Malicious versions of the popular rest-client gem were published after a credential compromise, adding a remote code-execution backdoor and credential exfiltration. Account compromiseRubyGemscriticalstrong_password2019A hijacked gem version fetched and executed remote code from pastebin, giving the attacker a persistent backdoor in Rails apps. Account compromiseRubyGemshighcolourama (typosquat of colorama)2018A typosquat of the popular colorama package hijacked the Windows clipboard to swap in the attacker's cryptocurrency wallet address. TyposquatPyPImediumeslint-scope2018A maintainer's account was compromised and a malicious eslint-scope version published that attempted to exfiltrate npm authentication tokens. Account compromisenpmhighevent-stream2018A new maintainer added a malicious dependency (flatmap-stream) that targeted the Copay bitcoin wallet, attempting to steal wallet credentials. Account compromisenpmhigh

Block malicious packages before they reach your build

Safeguard’s CI gate stops typosquats, compromised packages, and actively-exploited dependencies from merging — automatically.

Protect my pipeline free See pricing

A curated set of well-documented incidents, each mapped to a public advisory (OSV, GitHub Security Advisory, or CVE). This is a reference of notable attacks, not a live feed of every malicious package. See Credits & Data Sources.