CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Supply chain

Malicious packages

Open-source supply-chain compromises (malicious and typosquat packages) from the Open Source Security Foundation (OpenSSF) Malicious Packages project, published in Open Source Vulnerabilities (OSV) format. These are tracked as their own entity, keyed on the malicious-package identifier, and kept separate from the Common Vulnerabilities and Exposures (CVE) table: a malicious package has no CVE identity. A notable record has a named finder, a tracked story, or an origin beyond the boilerplate GitHub Advisory Database and OpenSSF Package Analysis feeds. Every other recent record stays counted and remains available in the CSV. This page carries metadata and links only. It never reproduces a package's code or payload, and each summary is the record's own text.

3,200 reported in the last 30 days: npm 3,087, PyPI 104, and crates.io 9; 1 tied to a story.2,372 notable records listed828 boilerplate-origin records (counted, not listed)Supply chainSource: OpenSSF Malicious Packages

Population: records whose newest valid publisher or modification date is 2026-08-14 through 2026-09-12, inclusive. Records without either date are retained as undated rather than treated as old.

Not a Common Vulnerabilities and Exposures (CVE) list. A malicious package has no CVE identity, so these records are tracked separately from the vulnerabilities table and are never mixed into it. Metadata and links only: this page never reproduces a package's code or payload.

Download all 3,200 rows as comma-separated values (CSV) for software composition analysis (SCA) tools

2,372 shown

Plus 828 malicious-package records this window have only boilerplate origins and no named finder or tracked story. They are counted but not listed here, and remain available in the CSV.

About this data

Records come from the Open Source Security Foundation (OpenSSF) Malicious Packages project, a community catalog of open-source supply-chain compromises in Open Source Vulnerabilities (OSV) format. They are a distinct entity from the Common Vulnerabilities and Exposures (CVE) table: a malicious package has no CVE identity, so this tracker keys them on the malicious-package identifier and never mixes them into the vulnerabilities table. This page lists every record with a named finder, a tracked story, or an origin beyond the boilerplate GitHub Advisory Database and OpenSSF Package Analysis feeds. It counts every other recent record and keeps the full population available in the CSV. A record is joined to a story only on an exact ecosystem and package-name match, never a loose text match. This page carries metadata and links only. It never reproduces a package's code or payload, and each summary is the record's own text.

Malicious-package data is theOpenSSF Malicious Packages, licensedApache-2.0, maintained by Open Source Security Foundation (OpenSSF), distributed through Open Source Vulnerabilities (OSV.dev). Individual finder credit is shown on each expanded record, which needs JavaScript. The compact index below carries only the identifier, name, and ecosystem, so a reader without JavaScript is not promised finder credit that this page cannot show.

Glossary