Security advisories
Verified supply-chain findings — every case is disclosed to the maintainer or vendor first. Malware and vulnerability findings are named on publication; credential-leak identities are revealed only after a coordinated-disclosure deadline. Credential values are always redacted.
akiflow-toolkit — scrapes your Akiflow session out of Chrome's credential store
@agentgates/cli — autonomous crypto/password agent that injects itself into your agent config
mecord-connect — remote-operator credential access behind a "ChatGPT automation" cover
loka-ai-router — install-time binary downloads and shell installers
@onescience/onecode — install-time dropper
A commercial AI sales-call CLI that sends its users' login credentials in plaintext HTTP to a hardcoded IP
seekcode — an npm “AI coding agent” that exfiltrates your DeepSeek API key via a typosquat endpoint
squeez — an npm package whose postinstall curl|sh-drops a remote script and native binary, then rewrites Claude Code hooks
alihelp.xyz / Shadow Code — a Firefox affiliate-commission-hijacking campaign across four AliExpress add-ons
AliExpress Rating & Fake Review Checker — a Firefox add-on that hijacks AliExpress affiliate commissions and reports your product clicks to alihelp.xyz, while declaring it collects no data
AliExpress Image and Video Downloader — a Firefox add-on that hijacks AliExpress affiliate commissions and reports your product clicks to alihelp.xyz, while declaring it collects no data
Search by Image: AliExpress & Alibaba — a Firefox add-on that silently hijacks AliExpress affiliate commissions with no consent, and requests access to every site you visit
AliHelp — a Firefox “AliExpress shopping assistant” that hijacks affiliate commissions and tracks your shopping
tsshare — a Tushare-impersonating PyPI client that hides its endpoint in base64 and exfiltrates your API token and a hardware fingerprint
orbitron-tui — a malicious AI-CLI impersonation that relays your API key, prompts and code to an attacker backend
orbitron-cli — a malicious AI-CLI impersonation that relays your API key, prompts and code to an attacker backend
agent-free — a malicious AI-CLI impersonation that relays your API key, prompts and code to an attacker backend
prime-coding-agent — a malicious AI-CLI impersonation that relays your API key, prompts and code to an attacker backend
A cluster of AI-coding-CLI impersonations (npm) that relay your API key, code and prompts to attacker backends
codebuff-cli — a codebuff impersonation that relays your API key, code and prompts to an attacker backend
@yancyyu/agentcli — a Feishu/Lark credential stealer with a keychain-decrypting telemetry worker
AzureCdnInfo.edrtester — a VS Code extension that beacons out with host recon behind HTTP Host-header domain fronting
Password-protected remote-fetch-and-execute dropper in the npm package cc-skills-helper (all 7 releases)
Supply-chain backdoor in the WordPress plugin Advanced Responsive Video Embedder (10.8.7)
Shai-Hulud / ChainDrop — self-propagating npm worm across 665 package versions
@types-beta/sdk — an import-time Windows RAT hiding behind the @types namespace
date-format-utils-xz — a metadata harvester that escalated to a reverse shell
faust-cont — an install-hook dropper that runs remote code via Deno
supplyhub — a postinstall SSH-key & credential stealer
tailwind-gutenberg-block-zero — an install-time Windows dropper posing as a Tailwind Gutenberg block
Dependency-confusion package that steals AWS, SSH and npm credentials from Across Protocol developers
npm package that steals your SSH keys, AWS creds and npm token on npm install
Fake “system metrics” npm package that opens a remote-command backdoor on npm install
Fake Polymarket MCP server that installs an SSH backdoor on npm install
Unauthenticated SQL Injection in the WordPress plugin Admin Note (1.1)
Unauthenticated SQL Injection in the WordPress plugin Auto Listings (2.7.3)
SQL Injection in the WordPress plugin WP Page Extension (1.1)
Unauthenticated SQL Injection in the WordPress plugin Voting for a photo (1.2)
Unauthenticated SQL Injection in the WordPress plugin Aeroscroll Gallery (1.0.13)
Unauthenticated SQL Injection in the WordPress plugin asAffili (1.1.1)
Fake React UI helper that steals your whole environment on install
Fake MetaMask (misspelled "metemask") SDK that steals your SSH keys and crypto wallets on install
Fake MetaMask SDK that steals your SSH keys and crypto wallets on install
Fake Binance SDK that steals your SSH keys and crypto wallets on install
Fake Solana SDK that steals your SSH keys and crypto wallets on install
Fake Jupiter (Solana DEX aggregator) SDK that steals your SSH keys and crypto wallets on install
Fake Orca (Solana DEX) SDK that steals your SSH keys and crypto wallets on install
Fake Meteora (Solana DEX) SDK that steals your SSH keys and crypto wallets on install
Fake Pump.fun SDK that steals your SSH keys and crypto wallets on install
Fake OpenSea SDK that steals your SSH keys and crypto wallets on install
Fake OpenSea SDK that steals your SSH keys and crypto wallets on install
Fake Polymarket SDK that steals your SSH keys and crypto wallets on install
Fake Polymarket SDK that steals your SSH keys and crypto wallets on install
Fake Hyperliquid SDK that steals your SSH keys and crypto wallets on install
Fake Hyperliquid SDK that steals your SSH keys and crypto wallets on install
Fake Polygon SDK that steals your SSH keys and crypto wallets on install
Fake Polygon SDK that steals your SSH keys and crypto wallets on install
Fake BNB Smart Chain (BSC) SDK that steals your SSH keys and crypto wallets on install
Fake BNB Smart Chain (BSC) SDK that steals your SSH keys and crypto wallets on install
Fake Ethereum SDK that steals your SSH keys and crypto wallets on install
Fake Ethereum SDK that steals your SSH keys and crypto wallets on install
Fake an Ethereum wallet library SDK that steals your SSH keys and crypto wallets on install
Fake web3.js SDK that steals your SSH keys and crypto wallets on install
Fake web3.js SDK that steals your SSH keys and crypto wallets on install
Fake web3.js SDK that steals your SSH keys and crypto wallets on install
Fake the campaign's own namesake handle SDK that steals your SSH keys and crypto wallets on install
Dependency-confusion probe that steals cloud credentials + your whole environment on install
A Steam “accelerator” extension that reads your Steam session and proxies your Steam traffic
A Chrome extension that strips Kling’s security headers to farm the AI service
A Chrome extension that strips a site’s security headers to farm an AI service
A bulk-mail & credential-cracking toolkit shipped as an npm package
A crypto-wallet & secret stealer disguised as an Autodesk Forge integration
Three live AI-provider keys shipped as an “inbuilt” free tier in LeetMentor
A download-and-execute dropper disguised as a date-formatting utility
A date-utility dropper — and the campaign it belongs to
Anatomy of an npm registry-hijack: /etc/hosts redirection and publish-token theft
Cloud-credential theft disguised as a React colour picker
A multi-stage credential stealer hiding inside a fake “zod-pino” utility