Confirmed malicious npm packages
Every package version the probe has confirmed malicious and published, newest first. 2,833 in total. Each links to the full advisory, with the analysis behind the verdict and its MITRE ATT&CK classification. Page 29 of 29.
- @open-banking/cabinet-providers@999.9.5 LWA-2026-1187T1195.002
- @easy-entry/landing-routes@99.9.5 LWA-2026-1222T1195.002
- @easy-entry/outside-registration-fop-navigator@99.9.5 LWA-2026-1223T1195.002
- @easy-entry/routes@99.9.5 LWA-2026-1224T1195.002
- @shell-cabinet/routes@99.9.5 LWA-2026-1225T1195.002
- @shell-landing/routes@99.9.5 LWA-2026-1226T1195.002
- @veertly/web-app@99.9.9 LWA-2026-1099T1195.002
- @digininja/key_stealer@1.0.1 LWA-2026-0232
- @digininja/key_stealer@1.0.2 LWA-2026-0233
- @digininja/postinstall@1.0.1 LWA-2026-0234
- @design-system-coopeuch/web@999.0.2 LWA-2026-0225
- @design-system-coopeuch/web@999.0.3 LWA-2026-0226
- @design-system-coopeuch/web@999.0.4 LWA-2026-0227
- @devcarron/clob@2.73.0 LWA-2026-0228
- @concerns/i18n@99.9.1 LWA-2026-0200T1195.002T1105
- @convera/ui-shared@0.0.2 LWA-2026-0201T1059T1546.016
- @convera/ui-shared@0.0.3 LWA-2026-0202T1059T1546.016
- @cryptobaby/cryptopapi@6.6.6 LWA-2026-0207T1027
- @cryptobaby/cryptopapi@6.6.7 LWA-2026-0208T1027
- @csp-frontend/dashboard@2.0.40 LWA-2026-0210
- @csp-frontend/auth@2.0.40 LWA-2026-0209
- @corpweb-ui/wmkt-library@99.99.11 LWA-2026-0203T1071.001
- @corpweb-ui/wmkt-library@99.99.12 LWA-2026-0204T1071.001
- @coterie-baby/common@99.9.1 LWA-2026-0205T1195.002T1105
- unleash-js@99.9.1 LWA-2026-0075T1195.002T1105
- msc-terminal@3.2.0 LWA-2026-0065T1059T1546.016
- @asavie/i18n@99.0.3 LWA-2026-0074T1059T1546.016
- wm-mapper@99.9.1 LWA-2026-0073T1195.002T1105
- @pisell/pisellos@2.2.164 LWA-2026-0033T1195.002
- @pisell/pisellos@2.2.168 LWA-2026-0034T1195.002
- @pisell/pisellos@2.2.169 LWA-2026-0035T1195.002
- @pisell/pisellos@2.2.173 LWA-2026-0036T1195.002
- forge-jsxy@1.0.91 LWA-2026-0060T1059T1546.016
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. The same findings are published as machine-readable OSV records, CC0, at github.com/leitwacht/malicious-packages. Think a finding is wrong? See the dispute policy.