22 notable real-world software supply-chain attacks — typosquats, account compromises, protestware, dependency-confusion, and backdoors — each with its impact and a public advisory reference.
22 incidents
A curated set of well-documented incidents, each mapped to a public advisory (OSV, GitHub Security Advisory, or CVE). This is a reference of notable attacks, not a live feed of every malicious package. See Credits & Data Sources.