Supply-chain incident tracker

Are you still shipping a compromised package?

Named npm, PyPI, and Cargo attacks where a specific package version was confirmed malicious. CodeTrawl matches a repo’s actual dependency tree against this curated list — so “are we affected?” gets a dated, cited answer instead of a shrug.

eslint-config-prettier supply-chain (2025)19 Jul 2025

Maintainer's npm token was phished; malicious versions executed an install.js that dropped a node-gyp.dll malware payload on Windows installs.

1 packagenpmCheck exposure →
@solana/web3.js supply-chain (December 2024)3 Dec 2024

Compromised maintainer token led to two malicious releases that exfiltrate Solana private keys at runtime.

1 packagenpmCheck exposure →
@lottiefiles/lottie-player supply-chain (October 2024)30 Oct 2024

Maintainer's npm credentials compromised; attackers published versions injecting a Web3 wallet-drainer into thousands of downstream sites.

1 packagenpmCheck exposure →
ctx (PyPI) takeover (May 2022)24 May 2022

Attacker took over the abandoned 'ctx' package on PyPI and published versions that exfiltrate environment variables (AWS keys, tokens) on import.

1 packagePyPICheck exposure →
rustdecimal typosquat (May 2022)10 May 2022

Typosquat of the legitimate 'rust_decimal' crate. Published to crates.io with a malicious binary payload that downloads + executes second-stage code.

1 packageCargoCheck exposure →
node-ipc protestware / wiper (March 2022)15 Mar 2022

Maintainer Brandon Nozaki Miller shipped versions that overwrite filesystem contents with heart emoji on machines geolocating to Russia or Belarus.

1 packagenpmCheck exposure →
colors.js / faker.js maintainer sabotage (January 2022)8 Jan 2022

Marak Squires intentionally pushed broken releases that print zalgo text and infinite-loop, breaking thousands of downstream builds.

2 packagesnpmCheck exposure →
rc supply-chain (November 2021)25 Nov 2021

Maintainer's npm token was compromised; attacker published malicious versions that ran a credential-stealing payload during install.

1 packagenpmCheck exposure →
ua-parser-js supply-chain (October 2021)22 Oct 2021

Maintainer's npm credentials were compromised; published versions installed a crypto-miner plus a password-stealing payload on Windows hosts.

1 packagenpmCheck exposure →
event-stream / flatmap-stream backdoor (November 2018)26 Nov 2018

A new maintainer added 'flatmap-stream' as a nested dependency; it shipped a backdoor that exfiltrated Bitcoin wallet credentials from the Copay app.

2 packagesnpmCheck exposure →

Curated from public advisories and post-mortems. Matching is manifest-scoped — it flags a compromised name@versionthat a repo still declares; it can’t see packages that entered off-manifest.