Software Supply Chain Attacks: 113 Real Examples
Updated 9 Oct 2026
113 case records, from 2009 to today. Every one arrived as a normal update from a source the world already trusted. Most had no CVE on day one.
Each attack has its own page with the affected versions, the sources, how to check your machine and what Vigilance shows on the poisoned release.
Recent supply chain attacks (2026)
These are the 19 supply chain attacks from 2026 in the library, newest first.
- Tensorlake npm SDK Shai-Hulud compromise 8 Oct 2026
- @apexacc/cli Defender-blinding C2 loader 17 Sept 2026
- arrayref / internment / append-only-vec crates.io compromise 20 Aug 2026
- keyv / cacheable npm worm (Shai-Hulud third wave) 4 Aug 2026
- SleeperGem dormant-maintainer RubyGems hijacks 18 Jul 2026
- Mastra AI npm compromise (Sapphire Sleet) 17 Jun 2026
- onering crate build-script code exfiltration 10 Jun 2026
- Microsoft durabletask PyPI compromise (TeamPCP) 19 May 2026
- Nx Console VS Code extension 18.95.0 compromise (TeamPCP / GitHub breach) 18 May 2026
- TanStack npm compromise (Mini Shai-Hulud) 11 May 2026
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- axios npm maintainer account takeover 31 Mar 2026
- LiteLLM PyPI backdoor (TeamPCP) 24 Mar 2026
- Trivy v0.69.4 and GitHub Actions compromise (TeamPCP) 19 Mar 2026
- Offside Wallet Theft Factory (Firefox add-ons converted from sports-score tools) 9 Mar 2026
- QuickLens / ShotBird ownership-transfer hijack 17 Feb 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
The most famous supply chain attacks
These cases have documented broad impact. The list is not a severity ranking.
- 3CX DesktopApp compromise One supply chain attack led to another
- SolarWinds Orion SUNBURST backdoor $50m in insurance payments
- CCleaner 5.33.6162 backdoor 2.27 million computers affected
- CCleaner backdoor (Piriform/Avast) 2.27 million computers affected
- M.E.Doc backdoor leading to NotPetya NotPetya reached 65 countries
- M.E.Doc update backdoor (NotPetya delivery) NotPetya reached 65 countries
npm attacks
-
8 Oct 2026
Tensorlake npm SDK Shai-Hulud compromise
npm
An AI company's software kit gained the ability to steal passwords and access keys during install, then spread itself through the victim's own packages.
-
17 Sept 2026
@apexacc/cli Defender-blinding C2 loaderVigilance
npm
A founder's AI tool gained the ability to switch off Windows Defender and Smart App Control from a hidden administrator window, then take orders from a server.
-
4 Aug 2026
keyv / cacheable npm worm (Shai-Hulud third wave)
npm
Installing the library now ran hidden code first that gathered cloud and login keys and re-published poisoned copies of other libraries.
-
17 Jun 2026
Mastra AI npm compromise (Sapphire Sleet)
npm
An AI toolkit gained a new hidden helper that installs remote-control software and hunts for cryptocurrency wallets.
-
11 May 2026
TanStack npm compromise (Mini Shai-Hulud)
npm
The package gained a new hidden file that ran during install, collected build secrets and sent them away.
-
31 Mar 2026
axios npm maintainer account takeover
npm
A hugely popular web-request library gained a new hidden helper that installs a remote-control program on your machine.
-
24 Nov 2025
Shai-Hulud 2.0 (second wave)
npm
The package can now download a second program before installing, gather the machine's cloud passwords, and infect more packages automatically.
-
8 Sept 2025
chalk / debug / ansi-styles maintainer phishing compromise
npm
A text-coloring helper can suddenly watch a web page's payment traffic and swap the destination of outgoing cryptocurrency payments.
-
26 Aug 2025
Nx s1ngularity compromise
npm
A build tool gained an install script that hunted for secrets, even asking local AI assistants to help.
-
18 Jul 2025
eslint-config-prettier / eslint-plugin-prettier phishing compromise
npm
A code-formatting settings package gained an install step that dropped and ran a hidden Windows program.
-
6 Jun 2025
gluestack / react-native-aria compromise
npm
User-interface components gained hidden code letting an outsider run commands on the developer's computer from far away.
-
5 May 2025
rand-user-agent RAT compromise
npm
A small text-generating helper gained hidden code that opened a permanent connection letting outsiders run commands.
-
21 Apr 2025
xrpl.js (XRP Ledger SDK) backdoor
npm
A cryptocurrency toolkit gained code that copied the secret phrase protecting a wallet and sent it to an outside website.
-
19 Dec 2024
Rspack / Vant npm token compromise
npm
A build tool's helper file can now find out where you are, then download and run a mining program.
-
30 Oct 2024
LottieFiles lottie-player compromise
npm
An animation player gained code that popped up a wallet sign-in box and moved visitors' cryptocurrency out.
-
1 Jul 2024
function-flag and the MALFEX npm campaign
npm
A small text-art package gained an install step that quietly downloaded and ran a hidden Windows program.
-
14 Dec 2023
Ledger Connect Kit wallet drainer
npm
A wallet-connection widget gained code that tricked visitors into approving transfers that emptied their cryptocurrency accounts.
-
4 Nov 2021
coa npm library hijack
npm
Installing this library now started a hidden program that fetched and ran a password-stealing file from the internet.
-
4 Nov 2021
rc npm library hijack
npm
Installing this settings library now launched a hidden downloader that pulled a password-stealing program onto the machine.
-
22 Oct 2021
ua-parser-js account hijack
npm
Installing the library now quietly downloaded and ran a program that mined coins and stole saved passwords.
-
5 Jul 2019
PureScript npm installer sabotage (load-from-cwd-or-npm, rate-map)
npm
One helper can now overwrite other packages' files on disk, quietly breaking a rival project's download step.
-
23 Mar 2019
electron-native-notify / Komodo Agama wallet attack
npm
The notification helper can now call a website, download extra code, and run it inside the wallet app.
-
9 Sept 2018
event-stream / flatmap-stream backdoor
npm
The library can now unscramble a hidden blob, run it, and plant extra code inside a bitcoin wallet app.
-
12 Jul 2018
eslint-scope / eslint-config-eslint credential theft
npm
Installing it now reached out to a website, ran whatever code it found there, and mailed off publishing keys.
-
12 Apr 2018
getcookies backdoor shipped through mailparser
npm
The email reader pulled in a hidden helper that let any visitor send commands and have them run.
-
12 Feb 2018
conventional-changelog crypto-miner publish
npm
Using the library now downloaded a hidden coin-mining program onto the machine and ran it in the background.
PyPI attacks
-
19 May 2026
Microsoft durabletask PyPI compromise (TeamPCP)
PyPI
A Microsoft workflow library gained code that, on import, downloaded and ran a hidden secret-stealing program.
-
24 Mar 2026
LiteLLM PyPI backdoor (TeamPCP)
PyPI
An AI gateway gained hidden code that stole cloud keys and login files, and started itself every time Python ran.
-
28 Jul 2025
num2words hijack (PyPI phishing campaign / Scavenger malware)
PyPI
A number-spelling library gained a hidden bundled program that stole files and gave outsiders lasting remote access to the machine.
-
4 Dec 2024
Ultralytics PyPI compromise (GitHub Actions cache poisoning)
PyPI
An image-recognition library gained code that downloaded and ran a hidden program using your computer to mine cryptocurrency.
-
20 Nov 2024
aiocpa crypto-pay library poisoned release
PyPI
A payments library gained hidden scrambled code that unpacked itself and sent the owner's payment keys to a chat bot.
-
20 Nov 2024
aiocpa PyPI infostealer implant
PyPI
A payments library gained heavily disguised code that copied the user's API password to a chat bot.
-
12 Apr 2024
pingdomv3 Revival Hijack
PyPI
A revived, previously abandoned monitoring helper gained hidden code that fetched and ran commands from a stranger's website during builds.
-
21 May 2022
ctx (PyPI) and phpass (Packagist) hijack
PyPI
A small helper library gained the ability to read the machine's stored cloud passwords and mail them to a stranger.
-
14 May 2022
ctx PyPI package hijack
PyPI
A tiny data-handling helper suddenly read every password stored in the computer's settings and mailed them to a stranger's website.
-
6 May 2018
SSH Decorator (ssh-decorate) backdoor
PyPI
A remote-login helper started copying the usernames, passwords and keys it handled and sending them to an outside website.
GitHub Actions attacks
-
19 Mar 2026
Trivy v0.69.4 and GitHub Actions compromise (TeamPCP)
CI action
A security scanner gained code that read secrets from the build machine's memory and sent them to a lookalike website.
-
14 Mar 2025
tj-actions/changed-files GitHub Action compromise
CI action
A build-automation step gained the ability to download a script that read secrets out of memory and printed them.
-
11 Mar 2025
reviewdog/action-setup compromise
CI action
An installer script gained hidden instructions that read the build system's secret passwords and wrote them into public logs.
Vendor binary attacks
-
6 May 2026
JDownloader official site installer swap
vendor binary
A download manager's setup file was rebuilt to also unscramble and run a hidden program that disables antivirus software.
-
9 Apr 2026
CPUID CPU-Z / HWMonitor download compromise
vendor binary
Hardware info tools' downloads gained an extra library that Windows loads automatically, which then contacted strangers and ran their software.
-
8 Apr 2026
DAEMON Tools trojanized installers
vendor binary
A disc-imaging tool's helper programs gained the ability to ask a stranger's website for commands and run them at startup.
-
20 Jan 2026
eScan antivirus update server compromise (2026)
vendor binary
An antivirus program's own updater file was swapped for one that calls strangers, downloads scrambled code, and blocks future repairs.
-
1 Aug 2025
QuickFox VPN trojanized Windows installer
vendor binary
A VPN app's main page file gained two lines that load hidden scripts, inspect the computer, and fetch a spying tool.
-
1 Jun 2025
Notepad++ update infrastructure compromise
vendor binary
A text editor's update quietly added an extra program that surveyed the computer and sent what it found to strangers.
-
12 May 2025
RVTools installer compromise (Bumblebee)
vendor binary
A server management tool's installer gained an extra file that Windows loads automatically, opening the computer to attackers.
-
1 Oct 2024
Procolored printer software malware distribution
vendor binary
Printer software downloads gained programs that record keystrokes, take screenshots, and swap copied payment addresses for the attacker's own.
-
5 Mar 2024
JAVS Viewer courtroom recorder backdoor
vendor binary
Courtroom recording software's installer gained a look-alike helper program that opened a remote connection and downloaded more attacker software.
-
20 Oct 2023
CyberLink installer compromise (Diamond Sleet)
vendor binary
A video app's installer gained hidden code that checks the clock, downloads a fake picture, unscrambles it and runs it.
-
13 Mar 2023
3CX DesktopApp compromise
vendor binary
A phone app's media file can unlock a hidden program, fetch instructions from the internet, and run them weeks later.
-
26 Sept 2022
Comm100 Live Chat trojanized installer
vendor binary
A chat program's startup script can download more code from the internet and open a command window for outsiders.
-
26 May 2022
MiMi chat app compromise (Iron Tiger)
vendor binary
A chat app's startup script gained scrambled code that quietly fetched and ran spy programs for Windows and Mac.
-
20 Apr 2021
Passwordstate In-Place Upgrade compromise
vendor binary
A password manager's own file can download extra code and ship the entire password vault to strangers.
-
8 Feb 2021
MonPass certificate authority client backdoor
vendor binary
A certificate tool's installer gained hidden code that downloads a picture, pulls a secret program out of it, and runs it.
-
16 Jan 2021
IObit forum DeroHE ransomware package
vendor binary
A free-licence giveaway package swapped one library for a version that locked every file on the computer and demanded payment.
-
1 Sept 2020
Operation NightScout (BigNox NoxPlayer)
vendor binary
An Android emulator's update gained an extra hidden file that opened remote control of the computer for a few chosen victims.
-
23 Jul 2020
Operation SignSight (Vietnam Government Certification Authority)
vendor binary
A government signing tool's installer gained an extra program that reported the computer's details and installed further add-ons on request.
-
24 Mar 2020
SolarWinds Orion SUNBURST backdoor
vendor binary
A monitoring program's own library can suddenly phone strangers, take orders from them, and quietly run whatever they sent.
-
24 Jan 2020
Free Download Manager Debian repository backdoor
vendor binary
The installer step gained code that drops two hidden programs and schedules them to phone out every ten minutes.
-
24 Jan 2020
Free Download Manager Linux package backdoor
vendor binary
A download tool's setup script gained the ability to drop two hidden programs and rerun them every ten minutes forever.
-
18 Jul 2018
Operation Red Signature (South Korean remote support vendor)
vendor binary
A support tool's update quietly added a new signed program that let outsiders control the machine and steal database passwords.
-
1 Jun 2018
ASUS Live Update (Operation ShadowHammer)
vendor binary
A laptop's own update helper can unpack hidden instructions and download extra software, but only onto a short list of chosen machines.
-
1 Jun 2018
ShadowHammer phase two: trojanized game and software vendors
vendor binary
Game programs players already trusted gained hidden code that contacted strangers and can fetch and run more software.
-
1 May 2018
Able Desktop (Operation StealthyTrident)
vendor binary
A business chat installer gained extra hidden files that unscrambled and ran spy software giving outsiders control of the computer.
-
19 Apr 2018
GuptiMiner hijack of eScan antivirus updates
vendor binary
An antivirus update package gained an extra library that pulled hidden code out of pictures and installed spying and mining software.
-
12 Feb 2018
MediaGet poisoned update (Dofoil/Smoke Loader outbreak)
vendor binary
A torrent program's update replaced it with a copy that quietly downloaded and ran coin-mining software.
-
19 Oct 2017
Eltima Elmedia Player / Folx Proton compromise
vendor binary
A media player download was rebuilt to also carry a spy program that steals passwords and gives outsiders remote access.
-
15 Aug 2017
CCleaner 5.33.6162 backdoor
vendor binary
The cleanup program gained hidden code that reports your computer's details to an outside server and can fetch more.
-
15 Aug 2017
CCleaner backdoor (Piriform/Avast)
vendor binary
A cleanup tool can send details about your computer to strangers and download extra programs chosen by them.
-
18 Jul 2017
ShadowPad in NetSarang Xmanager/Xshell
vendor binary
A server tool's networking file can unscramble a hidden program, ask outsiders for orders every eight hours, and steal logins.
-
22 Jun 2017
M.E.Doc backdoor leading to NotPetya
vendor binary
Accounting software's own library can read stored mail passwords, take remote orders, and launch programs that wiped whole companies.
-
2 May 2017
HandBrake for Mac / OSX.Proton
vendor binary
The video app was rebuilt to ask for your admin password and then hand your machine to strangers.
-
2 May 2017
HandBrake for Mac mirror compromise (Proton RAT)
vendor binary
A video converter download gained hidden code that asked for your Mac password and then let strangers log in remotely.
-
14 Apr 2017
M.E.Doc update backdoor (NotPetya delivery)
vendor binary
The tax software's update module gained code that steals mail passwords and quietly runs programs sent from outside.
-
29 Aug 2016
Transmission for Mac / OSX.Keydnap
vendor binary
A licence file inside the app was a program that steals saved passwords and keeps remote access.
-
4 Mar 2016
Transmission for Mac / KeRanger ransomware
vendor binary
A document file inside the app was secretly a program that locks your files and demands money.
-
9 Apr 2015
Kingslayer (Altair EvLog / EventID.net)
vendor binary
A log-reading tool for administrators can quietly open a channel to outsiders and pull down extra hidden software.
-
16 Apr 2014
Havex trojanized ICS vendor installers (Dragonfly)
vendor binary
Industrial equipment software installers gained an extra hidden file that phoned out and scanned the plant network for control devices.
Browser and IDE extension attacks
-
18 May 2026
Nx Console VS Code extension 18.95.0 compromise (TeamPCP / GitHub breach)
IDE extension
On opening any project folder the add-on ran a downloaded program that hunted for passwords and cloud keys.
-
9 Mar 2026
Offside Wallet Theft Factory (Firefox add-ons converted from sports-score tools)
browser extension
Harmless sports-score add-ons were replaced with fake wallet screens that captured the secret phrases people typed in.
-
17 Feb 2026
QuickLens / ShotBird ownership-transfer hijack
browser extension
The little search tool started taking orders from an outside server and running whatever code it sent back.
-
24 Dec 2025
Trust Wallet browser extension v2.68 compromise
browser extension
The wallet add-on gained code that grabbed your secret recovery words each time you unlocked it and sent them away.
-
17 Oct 2025
GlassWorm self-propagating worm on Open VSX / VS Code Marketplace
IDE extension
Invisible characters hid code that let the editor add-on steal developer passwords and open a secret door into the machine.
-
17 Jul 2025
Amazon Q Developer for VS Code malicious commit
IDE extension
The coding helper gained hidden instructions telling its assistant to run commands that erase files and cloud accounts.
-
27 Jun 2025
RedDirection campaign (Color Picker Geco and 17 others)
browser extension
After years as a harmless colour tool, it started reporting every page you opened and steering you elsewhere.
-
17 Jun 2025
ETHcode VS Code extension malicious pull request
IDE extension
One new helper package let the editor add-on quietly open a hidden shell and download and run a program.
-
25 Dec 2024
Cyberhaven Chrome extension compromise
browser extension
A browser add-on gained code that took instructions from a stranger's server and stole login cookies.
-
18 Dec 2024
December 2024 Chrome Web Store OAuth phishing wave (beyond Cyberhaven)
browser extension
Two new files let each add-on take orders from an outside server and quietly copy your saved logins away.
-
4 Jul 2024
GitLab-reported Chrome extension hijack wave (16 extensions, 3.2M users)
browser extension
The add-ons gained the ability to switch off page safety rules and drop outside code into sites you visit.
-
15 Oct 2020
Nano Adblocker / Nano Defender ownership sale and poisoned update
browser extension
A brand new file inside the ad blocker started reporting everything you did back to a server the new owners ran.
-
1 Oct 2020
The Great Suspender Chrome extension takeover
browser extension
A tab-saving add-on gained code that fetches instructions from an outside server and tracks every page you visit.
-
1 Oct 2020
The Great Suspender malicious maintainer takeover
browser extension
The tab-saver can now download and run fresh instructions from a website nobody had heard of, on every page you opened.
-
4 Sept 2018
MEGA Chrome extension compromise
browser extension
The file-sharing add-on asked for wider access, then watched login pages and mailed your passwords and wallet keys away.
-
2 Aug 2017
Web Developer for Chrome hijack (Proofpoint extension-hijacking spree)
browser extension
The developer toolbar suddenly fetched outside code and slipped adverts into every website its million users looked at.
-
29 Jul 2017
Copyfish Chrome extension hijack
browser extension
The text-grabbing add-on gained the ability to pull hidden code off the internet and paste adverts into every page you visited.
-
1 Jan 2014
Add to Feedly extension sold to adware operator
browser extension
New owners updated the button so it silently rewrote links on every site you visited to earn them money.
Other ecosystems: crates.io, RubyGems, Maven, NuGet and source tarballs
-
20 Aug 2026
arrayref / internment / append-only-vec crates.io compromise
crates.io
Three very common building-block libraries gained a new helper that downloaded and ran a stranger's program every time code was compiled.
-
18 Jul 2026
SleeperGem dormant-maintainer RubyGems hijacks
RubyGems
Dormant developer libraries woke up and gained code that downloaded and ran a stranger's program, then kept it running forever.
-
10 Jun 2026
onering crate build-script code exfiltration
crates.io
A queue library gained a new build step that copied the developer's latest code changes and sent them away.
-
24 Nov 2025
Shai-Hulud v2 reaches Maven Central via mvnpm mirror
Maven
An automatically mirrored Java copy of a JavaScript library gained a huge hidden script that hunted for and published secrets.
-
9 Jul 2025
Gravity Forms WordPress plugin compromise
other
A website form plugin's main file gained code that reports the site to strangers and runs whatever code they send back.
-
24 Feb 2024
XZ Utils backdoor
source tarball
A build helper file can now unpack a hidden program from a test file and run it while software compiled.
-
8 Aug 2023
Moq SponsorLink build-time email collection
NuGet
A very common testing library gained a hidden piece that read the developer's email address and sent it to a company server.
-
14 Aug 2019
rest-client gem backdoor (CVE-2019-15224)
RubyGems
A web-request library gained the ability to fetch and run code written by a stranger on any live server.
-
25 Jun 2019
strong_password gem hijack (CVE-2019-13354)
RubyGems
A password-strength checker, which never used the internet, gained the ability to fetch and run a stranger's code.
-
26 Mar 2019
bootstrap-sass RubyGems backdoor
RubyGems
The styling library can now read a visitor's cookie and run whatever hidden commands it contained on the server.
-
20 Dec 2018
PHP PEAR go-pear.phar installer backdoor
install script
The installer file gained hidden code that opens a remote command line back to an attacker's computer.
-
1 Apr 2018
Webmin SourceForge build backdoor
source tarball
A password-reset page in a server admin tool gained a hidden path that ran any command a stranger typed in.
-
20 Feb 2016
Linux Mint backdoored ISO
other
A whole operating system download gained a hidden program that joined a chat channel and waited for orders from strangers.
-
22 Sept 2012
phpMyAdmin 3.5.2.2 SourceForge mirror backdoor
source tarball
A new file appeared in the download that runs whatever code a visitor sends to it.
-
30 Jun 2011
vsftpd 2.3.4 backdoor
source tarball
The server gained a hidden door that opens a command prompt for anyone who types a smiley face.
-
28 Nov 2010
ProFTPD 1.3.3c source tarball backdoor
source tarball
The help command file can now give anyone full control of the server without a password.
-
1 Nov 2009
UnrealIRCd 3.2.8.1 tarball backdoor
source tarball
A header file gained a hidden rule letting anyone connecting to the chat server run commands on it.
Why supply chain attacks are hard to defend against
A supply chain attack is hard to stop because the bad code comes from a source you already trust. It arrives as a normal update. It often carries a valid signature, and it often has no CVE on the day it ships.
A scanner that looks for known bad code has nothing to match at that point. A file integrity tool sees that a file changed, but every update changes files. The question that matters is what the new version can do that the old one could not.
That is the question Vigilance answers. It compares the version you trust with the new one and names the file that gained a new capability. Read how to prevent supply chain attacks for the controls that work.
Frequently asked questions
What is an example of a supply chain attack?
The axios npm attack in March 2026 is one example. An attacker took over a maintainer account and published axios 1.14.1 and 0.30.4. Those versions added a new dependency that installed a remote access trojan. This library holds 113 more examples, each with its own page.
What is the most famous supply chain attack?
The SolarWinds Orion attack of 2020 is the most widely reported. A backdoor called SUNBURST shipped inside signed Orion updates to thousands of customers. Other well-known cases are NotPetya through M.E.Doc in 2017, CCleaner in 2017, 3CX in 2023 and the xz Utils backdoor in 2024.
Why are supply chain attacks difficult to defend against?
The malicious code arrives as a normal update from a source you already trust. It is often signed, it often has no CVE on the day it ships, and a scanner that looks for known bad code has nothing to match yet.
One entry here is a captured run on the real packages. The rest are rebuilt from public reports, in the words Vigilance prints, because the malicious releases are not redistributed. Not every supply chain attack works this way. Some change a value rather than a capability, and some never touch a file on your machine.