Confirmed malicious npm packages

Every package version the probe has confirmed malicious and published, newest first. 2,833 in total. Each links to the full advisory, with the analysis behind the verdict and its MITRE ATT&CK classification. Page 29 of 29.

  1. T1195.002
  2. @easy-entry/landing-routes@99.9.5 LWA-2026-1222
    T1195.002
  3. T1195.002
  4. @easy-entry/routes@99.9.5 LWA-2026-1224
    T1195.002
  5. @shell-cabinet/routes@99.9.5 LWA-2026-1225
    T1195.002
  6. @shell-landing/routes@99.9.5 LWA-2026-1226
    T1195.002
  7. @veertly/web-app@99.9.9 LWA-2026-1099
    T1195.002
  8. @digininja/key_stealer@1.0.1 LWA-2026-0232
  9. @digininja/key_stealer@1.0.2 LWA-2026-0233
  10. @digininja/postinstall@1.0.1 LWA-2026-0234
  11. @design-system-coopeuch/web@999.0.2 LWA-2026-0225
  12. @design-system-coopeuch/web@999.0.3 LWA-2026-0226
  13. @design-system-coopeuch/web@999.0.4 LWA-2026-0227
  14. @devcarron/clob@2.73.0 LWA-2026-0228
  15. @concerns/i18n@99.9.1 LWA-2026-0200
    T1195.002T1105
  16. @convera/ui-shared@0.0.2 LWA-2026-0201
    T1059T1546.016
  17. @convera/ui-shared@0.0.3 LWA-2026-0202
    T1059T1546.016
  18. @cryptobaby/cryptopapi@6.6.6 LWA-2026-0207
    T1027
  19. @cryptobaby/cryptopapi@6.6.7 LWA-2026-0208
    T1027
  20. @csp-frontend/dashboard@2.0.40 LWA-2026-0210
  21. @csp-frontend/auth@2.0.40 LWA-2026-0209
  22. @corpweb-ui/wmkt-library@99.99.11 LWA-2026-0203
    T1071.001
  23. @corpweb-ui/wmkt-library@99.99.12 LWA-2026-0204
    T1071.001
  24. @coterie-baby/common@99.9.1 LWA-2026-0205
    T1195.002T1105
  25. unleash-js@99.9.1 LWA-2026-0075
    T1195.002T1105
  26. msc-terminal@3.2.0 LWA-2026-0065
    T1059T1546.016
  27. @asavie/i18n@99.0.3 LWA-2026-0074
    T1059T1546.016
  28. wm-mapper@99.9.1 LWA-2026-0073
    T1195.002T1105
  29. @pisell/pisellos@2.2.164 LWA-2026-0033
    T1195.002
  30. @pisell/pisellos@2.2.168 LWA-2026-0034
    T1195.002
  31. @pisell/pisellos@2.2.169 LWA-2026-0035
    T1195.002
  32. @pisell/pisellos@2.2.173 LWA-2026-0036
    T1195.002
  33. forge-jsxy@1.0.91 LWA-2026-0060
    T1059T1546.016

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. The same findings are published as machine-readable OSV records, CC0, at github.com/leitwacht/malicious-packages. Think a finding is wrong? See the dispute policy.