Your RSA-2048 keys break in 2030. Find every one of them before attackers do.

Malware Database

Malicious open-source packages — supply-chain attacks, infostealers, backdoors, and typosquats across npm, PyPI, and other registries. Each advisory covers what the malware does, which versions are compromised, SHA-256 indicators of compromise, the attack campaign, and removal steps. Look up any package at /malware/{ecosystem}/{name}.

Recently discovered malicious packages

1cattunnelnpm

Sep 9, 2026

@aircanada/componentsnpm

Sep 9, 2026

@aircanada/corenpm

Sep 9, 2026

@aircanada/navigation-handlernpm

Sep 9, 2026

@aspect-adv-ui/consent-managernpm

Sep 9, 2026

@fdr-mar/promos-typesnpm

Sep 9, 2026

@haimiya/baileysnpm

Sep 9, 2026

@idkruan-10/dpd-depconf-probenpm

Sep 9, 2026

@jacksher/install-exec-pocnpm

Sep 9, 2026

@liuliang520500/sinataoke_cnnpm

Sep 9, 2026

@medisend/authnpm

Sep 9, 2026

@medisend/corenpm

Sep 9, 2026

@medisend/sharednpm

Sep 9, 2026

@medisend/webview-bridgenpm

Sep 9, 2026

@opap/player-kyc-widgetnpm

Sep 9, 2026

@umschool/analyticsnpm

Sep 9, 2026

@usemosaik/template-react-jsnpm

Sep 9, 2026

@vallensofficial/baileysnpm

Sep 9, 2026

@versacode/baileysnpm

Sep 9, 2026

@web2apk/baileysnpm

Sep 9, 2026

@yancyyu/agentclinpm

Sep 9, 2026

@yongot/canary-mcp-isolationnpm

Sep 9, 2026

@yongot/canary-mcp-testnpm

Sep 9, 2026

aedes_clustersnpm

Sep 9, 2026

afterpay-sdk-example-servernpm

Sep 9, 2026

alloy-graphqlnpm

Sep 9, 2026

array-framesnpm

Sep 9, 2026

array-scalanpm

Sep 9, 2026

b2b-frontend-external-librarynpm

Sep 9, 2026

base-account-corenpm

Sep 9, 2026

base-app-datanpm

Sep 9, 2026

blueai-clinpm

Sep 9, 2026

bmc-i18n-extract-clinpm

Sep 9, 2026

bmc-translate-utilsnpm

Sep 9, 2026

boardwalk-js-testsnpm

Sep 9, 2026

bx-ui-viewnpm

Sep 9, 2026

cb-wallet-analyticsnpm

Sep 9, 2026

cb-wallet-datanpm

Sep 9, 2026

cb-wallet-envnpm

Sep 9, 2026

cb-wallet-httpnpm

Sep 9, 2026

cb-wallet-metadatanpm

Sep 9, 2026

cb-wallet-solana-providernpm

Sep 9, 2026

cb-wallet-storenpm

Sep 9, 2026

chai-as-syncednpm

Sep 9, 2026

content-publisher-sdksnpm

Sep 9, 2026

date-fns-formatternpm

Sep 9, 2026

dbt-language-servernpm

Sep 9, 2026

dcftunnelnpm

Sep 9, 2026

digitalexp-style-module-l9npm

Sep 9, 2026

dojo-rn-interviewnpm

Sep 9, 2026

dynstrg-howtonpm

Sep 9, 2026

ecobee-apinpm

Sep 9, 2026

ecobee-homenpm

Sep 9, 2026

ecobee2npm

Sep 9, 2026

es6-migratornpm

Sep 9, 2026

eth-lib-helpersnpm

Sep 9, 2026

eth-query-utilsnpm

Sep 9, 2026

express-session-timernpm

Sep 9, 2026

feishu-docx-mcpnpm

Sep 9, 2026

fetch-page-assetsnpm

Sep 9, 2026

file-type-detectornpm

Sep 9, 2026

forge-extendednpm

Sep 9, 2026

gas-price-checkernpm

Sep 9, 2026

github-app-sts-actionnpm

Sep 9, 2026

glia-functions-toolsnpm

Sep 9, 2026

global-intelnpm

Sep 9, 2026

gloggonpm

Sep 9, 2026

hyper-kube-confignpm

Sep 9, 2026

i18nexus-toolsnpm

Sep 9, 2026

i18nexusnpm

Sep 9, 2026

jobber-app-template-reactnpm

Sep 9, 2026

jwt-loggernpm

Sep 9, 2026

karapace-docsnpm

Sep 9, 2026

kelly-stake-sizingnpm

Sep 9, 2026

kiki-baileysnpm

Sep 9, 2026

knowledge-gradernpm

Sep 9, 2026

krdpass-auth-react-nativenpm

Sep 9, 2026

llm-traces-appnpm

Sep 9, 2026

log-update-tsnpm

Sep 9, 2026

matlab-azure-devops-extensionnpm

Sep 9, 2026

megan-baileysnpm

Sep 9, 2026

multicore-kitnpm

Sep 9, 2026

node-helpernpm

Sep 9, 2026

oce-configurator-wireless-frontendnpm

Sep 9, 2026

ocfe-tv-subscription-center-webnpm

Sep 9, 2026

octopus-actionnpm

Sep 9, 2026

omni-channel-configurator-wireline-frontendnpm

Sep 9, 2026

omni-channel-oid-frontendnpm

Sep 9, 2026

omni-channel-order-frontendnpm

Sep 9, 2026

op-ts-server-corenpm

Sep 9, 2026

open-item-validatornpm

Sep 9, 2026

openai-pr-reviewernpm

Sep 9, 2026

optimizely-starter-kit-for-fastly-computenpm

Sep 9, 2026

oscar-redisnpm

Sep 9, 2026

passkeys-reactnpm

Sep 9, 2026

paypal-postman-libnpm

Sep 9, 2026

prism-registrynpm

Sep 9, 2026

punypumpnpm

Sep 9, 2026

puppeteer-obscuranpm

Sep 9, 2026

redis-type-intelnpm

Sep 9, 2026

remove-bg-serverless-azurenpm

Sep 9, 2026

rojo-rbxnpm

Sep 9, 2026

scw-corenpm

Sep 9, 2026

scw-mobilenpm

Sep 9, 2026

selfcertsnpm

Sep 9, 2026

service-homenpm

Sep 9, 2026

shadowx-fcanpm

Sep 9, 2026

simplisafe-gatsbynpm

Sep 9, 2026

sonmorsnpm

Sep 9, 2026

starship-timelinenpm

Sep 9, 2026

tailwind-aspect-stylesnpm

Sep 9, 2026

tailwindcss-aspectratio-stylesnpm

Sep 9, 2026

technical-challengenpm

Sep 9, 2026

tidal-embed-playernpm

Sep 9, 2026

tool-registry-scriptsnpm

Sep 9, 2026

toru-ultimatenpm

Sep 9, 2026

triage_bot_using_sdkv3npm

Sep 9, 2026

twilio-voice-js-reference-componentsnpm

Sep 9, 2026

unifi-credential-servernpm

Sep 9, 2026

uol-simple-api-futebolnpm

Sep 9, 2026

vinzz-wclinpm

Sep 9, 2026

vishal_312pkgnpm

Sep 9, 2026

wallet-cds-webnpm

Sep 9, 2026

wallet-engine-signingnpm

Sep 9, 2026

wolverinechatnpm

Sep 9, 2026

cv-trainPyPI

Sep 9, 2026

dac-toolsPyPI

Sep 9, 2026

metricboxlitePyPI

Sep 9, 2026

telegram-helperPyPI

Sep 9, 2026

tssharePyPI

Sep 9, 2026

Frequently asked questions

What is a malicious package?

A malicious package is a library published to an open-source registry (npm, PyPI, etc.) that contains harmful code — a credential stealer, backdoor, or data exfiltrator — often disguised as a useful tool or typosquatting a popular package. Unlike a vulnerability, you don't patch it; you remove it and rotate any secrets it could reach.

How do I know if a package I use is malicious?

Look it up here at /malware/{ecosystem}/{name} (for example, /malware/pypi/embiggen). If the package is flagged, the page lists the malicious versions, what the code does, and the indicators of compromise. You can also scan your whole dependency tree with O3 Security to catch malicious packages at install time and in CI.

What should I do if I installed a malicious package?

Remove it from your project and lockfile immediately, then assume any secrets the build or runtime could reach were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound network activity or persistence. Match the published SHA-256 IOCs against your package cache and build artifacts to confirm exposure.

Which registries does this cover?

npm, PyPI, Go, Maven, RubyGems, crates.io (Rust), NuGet, and other ecosystems tracked in the OSV malicious-packages dataset. New advisories appear here within hours of being published.

Where does this malware data come from?

From OSV's public MAL- advisory namespace, fed by the OpenSSF malicious-packages project — and many of the advisories you'll see credit O3 Security as the finder, from our own supply-chain research.

Block malicious packages before they install

O3 Security checks every dependency against known-malicious package intelligence at install time and in CI — stopping packages like these before any post-install script runs.

Supply-chain protection