Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-07 · updated: 2026-10-07 · tags: [incident, global, supply-chain] · confidence: high · severity: critical · affected_sectors: [global] · au_impact: true

The OpenSourceMalware archive flags a fresh cohort of verified malicious npm assets dated 6 October, distinct from this week's RubyGems crypto-key campaign. Standouts include @subql/common 5.8.3 — a compromised maintainer account pushed a postinstall script decoding an obfuscated infostealer blob (OSV: MAL-2026-17571); tailwindcss-forms-styles, which copies the legitimate @tailwindcss/forms plugin's code verbatim as cover above an IIFE with code-execution and exfiltration (MAL-2026-17524); plus dotenv-promises, with-cte, checkmate-remediation-assistant and serpacksven2, the latter rated "fully compromised if installed." All four-stage human-verified. Ecosystem consumers should treat these as active typosquat/infostealer supply-chain risk rather than noise, and check dependency lockfiles against the advisory OSV/GHSA records.

Attribute Detail
Sector Global (Macro)
Date 2026-10-07
Source OpenSourceMalware — @subql/common
Reliability Tier 2