Confirmed malicious npm packages
Every package version the probe has confirmed malicious and published, newest first. 2,833 in total. Each links to the full advisory, with the analysis behind the verdict and its MITRE ATT&CK classification. Page 13 of 29.
- nagix-node@2.1.6 LWA-2026-7193
- @ghost_debugger/nanocache@0.1.1 LWA-2026-7192T1195.002T1059.007T1105T1071.001T1573
- blots@2.1.0 LWA-2026-7188T1059.004T1082T1041
- voicemail@1.0.1 LWA-2026-7187T1059T1082T1071.001T1041
- toll_free@1.0.1 LWA-2026-7186T1059.007T1082T1041T1071.001
- fdd41@1.0.0 LWA-2026-7185T1059.001T1059.007T1053.005T1564.003T1036.005
- chain-analyze@1.0.2 LWA-2026-7183T1195.002T1059.007T1105T1071.001T1204.002
- fluid-type-ui@2.0.8 LWA-2026-7182T1195.002T1059.007T1082T1071.001T1573
- @adominadmininstr/fmt-date-helper@1.0.0 LWA-2026-7181T1195.002T1059.007T1082T1615T1552.001
- @adominadmininstr/date-util-helper@1.0.0 LWA-2026-7180T1195.002T1059.007T1082T1615T1071.001
- array-sort-helper@1.0.0 LWA-2026-7179T1195.002T1059.007T1082T1087.001T1615
- json-to-table-util@1.0.0 LWA-2026-7178T1059.007T1082T1083T1614T1071.001
- style-class-utils@1.0.0 LWA-2026-7176T1195.002T1059.007T1082T1615T1071.001
- text-line-parser@1.0.0 LWA-2026-7177T1195.002T1059.007T1082T1087.001T1057
- csv-parser-helper@1.0.0 LWA-2026-7175T1195.002T1059.007T1082T1071.001T1041
- css-animation-utils@1.0.1 LWA-2026-7174T1195.002T1059.007T1105T1071.001T1027
- num-format-helper@1.0.0 LWA-2026-7173T1195.002T1059.007T1082T1613T1552.001
- date-sanitize-helper@1.0.0 LWA-2026-7172T1195.002T1059.007T1082T1087.001T1057
- api-node-sdk@2.1.6 LWA-2026-7168T1195.002T1059.007T1098.004T1552.001T1082
- data-format-helper@1.0.1 LWA-2026-7169T1195.002T1059.007T1082T1615T1552.001
- chart-data-utils@1.0.0 LWA-2026-7170T1195.002T1059.007T1082T1087.002T1552.001
- color-convert-helper@1.0.0 LWA-2026-7167T1195.002T1059.007T1082T1615T1552.001
- @test1230504/string-format-helper@1.0.0 LWA-2026-7165T1059.007T1082T1041T1071.001
- simple-probe-utils@1.0.0 LWA-2026-7164T1059.007T1082T1071.001T1041
- @test1230504/probe-7f3k2m-utils@1.0.0 LWA-2026-7163T1059.007T1082T1041T1071.001
- api-rust-sdk@2.1.6 LWA-2026-7162T1195.002T1059.007T1098.004T1082T1005
- app-svm-layer@2.1.6 LWA-2026-7161T1195.002T1059.007T1098.004T1082T1083
- react-puller@1.0.0 LWA-2026-7160T1195.002T1059.007T1105T1547.001T1204.002
- app-soda-layer@2.1.6 LWA-2026-7159T1195.002T1059.007T1082T1005T1098.004
- @sqlite-table/schema-generator@1.0.2 LWA-2026-7156T1195.002T1059.007T1105T1071.001
- @sqlite-prime/createsql@1.0.0 LWA-2026-7155T1195.002T1059.007T1105T1071.001
- umber-root@1.1.2 LWA-2026-7154T1195.002T1059.007T1105T1071.001
- npm-wold@1.1.1 LWA-2026-7152T1195.002T1059.007T1105T1071.001
- @feui-render/feui-render@99.0.0 LWA-2026-7151T1195.002
- animate-css-vite@1.0.1 LWA-2026-7150T1195.002T1059.007T1105T1071.001
- @bobfrankston/rmfmail@1.2.178 LWA-2026-7148
- @bobfrankston/rmfmail@1.2.177 LWA-2026-7147
- jobber-app-template-react@1.0.1 LWA-2026-7146T1059.007T1082T1071.001T1041
- vscode-designer-14@14.0.1 LWA-2026-7145T1195.002T1059.007T1082T1005T1041
- glia-functions-tools@0.2.1 LWA-2026-7144T1059.007T1082T1071.001T1041
- encrypt-string-safe@2.2.0 LWA-2026-7139
- encrypt-string-safe@2.1.0 LWA-2026-7140T1195.002T1059.007T1105T1071.001
- streak-daily-lib@1.0.0 LWA-2026-7138
- dateuuidv2@1.0.0 LWA-2026-7137T1195.002T1059.007T1105T1071.001T1082
- messenger-style@1.0.1 LWA-2026-7136T1059.007T1082T1005T1041T1071.001
- dynstrg-howto@1.0.1 LWA-2026-7135T1195.002T1059.007T1082T1071.001T1041
- @ks-radar/radar@21.0.0 LWA-2026-7132T1059.007T1082T1041T1071.001
- basic-vite@1.0.0 LWA-2026-7131T1059.007T1082T1087.001T1012T1041
- compress-edge@1.0.0 LWA-2026-7130T1195.002
- swiper_angular@5.9999.0 LWA-2026-7128
- stargateproxyserv@28.0.0 LWA-2026-7119
- fundraiserservicepp@1.7.0 LWA-2026-7117
- fundraiserserv@28.0.0 LWA-2026-7125T1059T1546.016
- page-navigation@1.0.1 LWA-2026-7126T1195.002T1059.007T1082T1005T1041
- xo-member-components@28.0.0 LWA-2026-7124T1195.002T1059.007T1082T1071.001T1041
- merchantprefsservice-paypal@28.0.0 LWA-2026-7122T1195.002T1059.007T1082T1071.001T1041
- preferenceslifecycle-paypal@28.0.0 LWA-2026-7123
- identityauthorizationserv@28.0.0 LWA-2026-7120T1195.002T1059.007T1082T1071.001T1041
- payoutsvettingserv-paypal@28.0.0 LWA-2026-7118
- fundraiserservpp@1.9.0 LWA-2026-7116T1195.002T1059.007T1082T1071.001T1041
- @dhyas23/dicitaz-baileys@1.0.0 LWA-2026-7115T1195.002T1059.007
- app-sima-layer@2.1.6 LWA-2026-7114T1098.004
- @kite-js-tools/core@1.0.0 LWA-2026-7113T1195.002T1059.007T1082T1071.001T1041
- @cybs_forus/test@1.0.0 LWA-2026-7111T1059.007T1082T1041T1071.004
- clerk-next-fix-auth-protection@7.7.7 LWA-2026-7109T1195.002T1059.007T1082T1071.001T1041
- app-sim-layer@2.1.6 LWA-2026-7108T1195.002T1059.007T1082T1098T1005
- app-node-layer@2.1.6 LWA-2026-7101T1195.002T1059.007T1082T1005T1041
- shift-v4-sdk@1.0.5 LWA-2026-7099T1059.007T1082T1033T1071.001T1041
- shift-sdk-v5@5.0.1 LWA-2026-7100T1195.002T1059.007T1082T1033T1614
- shiftmarkets-sdk@2.1.0 LWA-2026-7098T1195.002T1059.007T1082T1049T1071.001
- @cryptosrvc/shift-exchange-root@3.9.9 LWA-2026-7096T1195.002T1059.007T1082T1041T1071.001
- @cryptosrvc/shift-sdk-v4@1.0.77 LWA-2026-7095T1059.007T1082T1016T1071.001T1041
- @cryptosrvc/no-brainer-sdk@1.0.18 LWA-2026-7097T1059.007T1082T1071.001T1041
- @shiftmarkets/shift-sdk-v4@1.0.77 LWA-2026-7094T1195.002T1059.007T1082T1518.001T1071.001
- @shiftmarkets/no-brainer-sdk@1.0.18 LWA-2026-7093T1195.002T1059.007T1082T1071.001T1041
- @shiftmarkets/shift-exchange-root@3.9.9 LWA-2026-7092T1059.007T1082T1016T1071.001T1041
- chai-as-rendered@1.2.0 LWA-2026-7091T1195.002T1059.007T1105T1071.001T1573
- gekko-mev-bot@1.0.0 LWA-2026-7090T1195.002T1059.007T1082T1005T1555.003
- @daylightqc/date-fmt-lite@1.1.2 LWA-2026-7085T1195.002T1059.007T1059T1082T1083
- cors-version@1.0.1 LWA-2026-7088
- cors-version@1.0.3 LWA-2026-7083
- cors-version@1.0.2 LWA-2026-7084T1195.002T1059.007T1105T1071.001
- system-performance-helper@1.0.1 LWA-2026-7082T1195.002T1059.007T1059T1547.001T1053.003
- express-dever@5.1.7 LWA-2026-7081T1195.002T1059.007T1059T1564.003T1485
- luluking3@0.0.1 LWA-2026-7078T1059.007T1105T1071.001
- block_package@1.0.0 LWA-2026-7076T1059.007T1105T1204.002
- stellar-api-safe@1.0.8 LWA-2026-7075T1195.002T1059T1552.001T1082T1071.001
- rollup-packages-node-polyfills@0.0.1 LWA-2026-7073T1195.002T1059.007T1105
- @bobfrankston/rmfmail@1.2.172 LWA-2026-7068
- @bobfrankston/rmfmail@1.2.168 LWA-2026-7064
- @bobfrankston/rmfmail@1.2.171 LWA-2026-7067
- @bobfrankston/rmfmail@1.2.170 LWA-2026-7066
- @bobfrankston/rmfmail@1.2.169 LWA-2026-7065
- tick-forge@11.5.2 LWA-2026-7063T1195.002T1059.007T1105T1071.001
- ambera@1.0.0 LWA-2026-7060T1195.002T1105T1059.007T1071.001
- @tobyvalk123/tixte@1.0.2 LWA-2026-7059T1195.002T1059.007T1082T1552.001T1041
- tracker-radar-detector@1.0.1 LWA-2026-7055T1059.007T1082T1071.001T1041
- react-fontawesome-icons@1.0.5 LWA-2026-7053T1195.002T1059.007T1539T1071.001T1041
- gekko-trading-bot@4.2.0 LWA-2026-7052T1195.002T1059.007T1105T1071.001
- fastify-client-bundler@1.4.0 LWA-2026-7051T1195.002T1059.007T1105T1071.001
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. The same findings are published as machine-readable OSV records, CC0, at github.com/leitwacht/malicious-packages. Think a finding is wrong? See the dispute policy.