Confirmed malicious npm packages

Every package version the probe has confirmed malicious and published, newest first. 3,262 in total. Each links to the full advisory, with the analysis behind the verdict and its MITRE ATT&CK classification. Page 33 of 33.

  1. @catamania/front-components@1.0.2 LWA-2026-2164
    T1059T1546.016
  2. jingmeideshishi@1.0.7 LWA-2026-2153
  3. masterkrweb@9.9.9 LWA-2026-2005
    T1071.001
  4. apache-httpclient7@1.0.0 LWA-2026-1318
  5. apache-httpclient6@1.0.0 LWA-2026-1317
  6. apache-httpclient5@1.0.0 LWA-2026-1316
  7. apache-httpclient4@1.0.0 LWA-2026-1315
  8. apache-httpclient3@1.0.0 LWA-2026-1314
  9. apache-httpclient2@1.0.0 LWA-2026-1313
  10. apache-httpclient1@1.0.0 LWA-2026-1312
  11. lsp-mcp@0.0.4 LWA-2026-1309
  12. amplitude-ma-ts@1.0.24 LWA-2026-1297
  13. amplitude-ma-ts@1.0.22 LWA-2026-1296
  14. @gbrlxvi/ts-form-utils@2.0.0 LWA-2026-1290
  15. alya-baileys@1.8.42 LWA-2026-1278
  16. alya-baileys@1.8.41 LWA-2026-1277
  17. alya-baileys@1.8.40 LWA-2026-1276
  18. alya-baileys@1.8.39 LWA-2026-1275
  19. alya-baileys@1.8.36 LWA-2026-1274
  20. alya-baileys@1.8.35 LWA-2026-1272
  21. alice-baileys@2.0.3 LWA-2026-1270
  22. alice-baileys@2.0.2 LWA-2026-1269
  23. alice-baileys@2.0.1 LWA-2026-1268
  24. alice-baileys@2.0.0 LWA-2026-1267
  25. aixj-cli@1.0.1 LWA-2026-1252
  26. @veertly/web-app@100.0.2 LWA-2026-1098
    T1195.002
  27. @veygo/component-library@99.9.2 LWA-2026-1112
    T1195.002
  28. T1195.002
  29. @visonum/network-quality-sdk@99.9.9 LWA-2026-1117
    T1195.002
  30. T1195.002
  31. @easy-entry/landing-routes@99.9.5 LWA-2026-1222
    T1195.002
  32. T1195.002
  33. @easy-entry/routes@99.9.5 LWA-2026-1224
    T1195.002
  34. @shell-cabinet/routes@99.9.5 LWA-2026-1225
    T1195.002
  35. @shell-landing/routes@99.9.5 LWA-2026-1226
    T1195.002
  36. @veertly/web-app@99.9.9 LWA-2026-1099
    T1195.002
  37. @digininja/key_stealer@1.0.1 LWA-2026-0232
  38. @digininja/key_stealer@1.0.2 LWA-2026-0233
  39. @digininja/postinstall@1.0.1 LWA-2026-0234
  40. @design-system-coopeuch/web@999.0.2 LWA-2026-0225
  41. @design-system-coopeuch/web@999.0.3 LWA-2026-0226
  42. @design-system-coopeuch/web@999.0.4 LWA-2026-0227
  43. @devcarron/clob@2.73.0 LWA-2026-0228
  44. @concerns/i18n@99.9.1 LWA-2026-0200
    T1195.002T1105
  45. @convera/ui-shared@0.0.2 LWA-2026-0201
    T1059T1546.016
  46. @convera/ui-shared@0.0.3 LWA-2026-0202
    T1059T1546.016
  47. @cryptobaby/cryptopapi@6.6.6 LWA-2026-0207
    T1027
  48. @cryptobaby/cryptopapi@6.6.7 LWA-2026-0208
    T1027
  49. @csp-frontend/dashboard@2.0.40 LWA-2026-0210
  50. @csp-frontend/auth@2.0.40 LWA-2026-0209
  51. @corpweb-ui/wmkt-library@99.99.11 LWA-2026-0203
    T1071.001
  52. @corpweb-ui/wmkt-library@99.99.12 LWA-2026-0204
    T1071.001
  53. @coterie-baby/common@99.9.1 LWA-2026-0205
    T1195.002T1105
  54. unleash-js@99.9.1 LWA-2026-0075
    T1195.002T1105
  55. msc-terminal@3.2.0 LWA-2026-0065
    T1059T1546.016
  56. @asavie/i18n@99.0.3 LWA-2026-0074
    T1059T1546.016
  57. wm-mapper@99.9.1 LWA-2026-0073
    T1195.002T1105
  58. @pisell/pisellos@2.2.164 LWA-2026-0033
    T1195.002
  59. @pisell/pisellos@2.2.168 LWA-2026-0034
    T1195.002
  60. @pisell/pisellos@2.2.169 LWA-2026-0035
    T1195.002
  61. @pisell/pisellos@2.2.173 LWA-2026-0036
    T1195.002
  62. forge-jsxy@1.0.91 LWA-2026-0060
    T1059T1546.016

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. The same findings are published as machine-readable OSV records, CC0, at github.com/leitwacht/malicious-packages. Think a finding is wrong? See the dispute policy.