CYBERSECURITYTRACKER
TRACKING3,014 stories541 vuln stories
Supply chain

Malicious packages

Open-source supply-chain compromises (malicious and typosquat packages) from the Open Source Security Foundation (OpenSSF) Malicious Packages project, published in Open Source Vulnerabilities (OSV) format. These are tracked as their own entity, keyed on the malicious-package identifier, and kept separate from the Common Vulnerabilities and Exposures (CVE) table: a malicious package has no CVE identity. Thousands of packages are auto-detected every week, so this page lists only the higher-signal records (reported by a named source, carrying references, or joined to a story here) and counts the bulk auto-detections honestly. This page carries metadata and links only. It never reproduces a package's code or payload, and each summary is the record's own text.

3,475 notable records listed41 auto-detected (counted, not listed)3,516 in the recent windowSupply chainSource: OpenSSF Malicious Packages

Not a Common Vulnerabilities and Exposures (CVE) list. A malicious package has no CVE identity, so these records are tracked separately from the vulnerabilities table and are never mixed into it. Metadata and links only: this page never reproduces a package's code or payload.

Plus 41 auto-detected malicious packages this window, counted but not listed here to keep this page high-signal. The full set is available in the source data below.

About this data

Records come from the Open Source Security Foundation (OpenSSF) Malicious Packages project, a community catalog of open-source supply-chain compromises in Open Source Vulnerabilities (OSV) format. They are a distinct entity from the Common Vulnerabilities and Exposures (CVE) table: a malicious package has no CVE identity, so this tracker keys them on the malicious-package identifier and never mixes them into the vulnerabilities table. Because thousands of packages are auto-detected each week, this page lists only the higher-signal records, those reported by a named source, carrying references, or joined to a story tracked here, and counts the bulk auto-detections honestly rather than flooding the page with them. A record is joined to a story only on an exact ecosystem and package-name match, never a loose text match. This page carries metadata and links only. It never reproduces a package's code or payload, and each summary is the record's own text.

Malicious-package data is theOpenSSF Malicious Packages, licensedApache-2.0, maintained by Open Source Security Foundation (OpenSSF), distributed through Open Source Vulnerabilities (OSV.dev). Individual finder credit is shown on each record.