This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries.
1. @andrewstory18/is-real-odd (npm)
* Package: https://www.npmjs.com/package/@andrewstory18/is-real-odd
* Severity: high
* Affected versions: all
* Downloads: 2460805
* First seen: 1 August 2026 at
This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries.
1. yuinpm (npm)
* Package: https://www.npmjs.com/package/yuinpm
* Severity: high
* Affected versions: 0.0.1-security
* Downloads: 7767
* First seen: 23 July 2026 at
This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries.
1. crypto-hasher (npm)
* Package: https://www.npmjs.com/package/crypto-hasher
* Severity: high
* Affected versions: 0.0.1-security
* Downloads: 1731879
* First seen: 15 July 2026 at
This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries.
1. @andrewstory18/is-real-odd (npm)
* Package: https://www.npmjs.com/package/@andrewstory18/is-real-odd
* Severity: high
* Affected versions: all
* Downloads: 1463379
* First seen: 10 July 2026 at
This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries.
1. zhuanhua (npm)
* Package: https://www.npmjs.com/package/zhuanhua
* Severity: medium
* Affected versions: all
* Downloads: 9165
* First seen: 1 July 2026 at 22:55
This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries.
1. @immobiliarelabs/backstage-plugin-gitlab-backend (npm)
* Package: https://www.npmjs.com/package/@immobiliarelabs/backstage-plugin-gitlab-backend
* Severity: critical
* Affected versions: 3.0.3, 4.0.2, 5.2.1,
This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries.
1. @mastra/client-js (npm)
* Package: https://www.npmjs.com/package/@mastra/client-js
* Severity: critical
* Affected versions: 1.24.1
* Downloads: 250837
* First seen: 17 June
Most teams think about dependency risk in terms of CVEs, malware, and typosquatting. But there is another kind of supply-chain risk that can hit just as hard: a package you already trust can change its license in a later release, turning a