DepWall

Advisories

Real supply-chain incidents, and what DepWall's engine actually returns for each one.

Every verdict below is recomputed by replaying the incident through the live signals engine when this page is generated. None of them is a remembered claim, which is why a row can say the engine missed something — and some do.

These are documents. DepWall's client does not read this page, and nothing here changes a verdict on your machine: a feed the scanner trusted would be a way to attack the scanner.

Generated 2026-08-08 from 9 incidents in the regression corpus.

DepWall's verdict is recomputed, not recorded. Sorted newest first.
ID Disclosed Severity Class Incident DepWall
DW-2026-0009 2026-08-04 CRITICAL Attested build, poisoned source keyv/cacheable maintainer compromise (Aug 2026) — malicious release carrying valid npm provenance BLOCK
DW-2026-0005 2026-06-09 CRITICAL Worm Mini Shai-Hulud (TeamPCP), 2026-05-11 — dead-man-switch / wiper stage BLOCK
DW-2026-0006 2026-06-09 CRITICAL Worm Mini Shai-Hulud (TeamPCP), npm/PyPI worm, 2026-05-11 — CI credential-theft stage BLOCK
DW-2026-0007 2026-06-09 CRITICAL Worm Mini Shai-Hulud (TeamPCP), npm/PyPI worm, 2026-05-11 ASK
DW-2026-0008 2026-06-02 HIGH Tarball substitution npm preinstall loader whose payload lives in the tarball ([email protected], discovered 2024-12-14) ASK
DW-2026-0003 2022-03-15 HIGH Protestware node-ipc protestware (March 2022, 'peacenotwar') ALLOW missed
DW-2026-0001 2021-10-22 CRITICAL Account takeover ua-parser-js account compromise (Oct 2021, CISA alert) BLOCK
DW-2026-0002 2018-11-26 CRITICAL Dependency takeover event-stream / flatmap-stream (Nov 2018) BLOCK
DW-2026-0004 2017-08-01 HIGH Typosquat crossenv / cross-env typosquat wave (Aug 2017) BLOCK

Detail

DW-2026-0009

keyv/cacheable maintainer compromise (Aug 2026) — malicious release carrying valid npm provenance

Disclosed
2026-08-04
Severity
CRITICAL
Class
Attested build, poisoned source

DepWall returns BLOCK on attestation, install-scripts, known-malicious.

Regression fixture keyv-provenance-signed-compromise.json · reference

DW-2026-0005

Mini Shai-Hulud (TeamPCP), 2026-05-11 — dead-man-switch / wiper stage

Disclosed
2026-06-09
Severity
CRITICAL
Class
Worm

DepWall returns BLOCK on install-scripts.

Regression fixture mini-shai-hulud-wiper.json · reference

DW-2026-0006

Mini Shai-Hulud (TeamPCP), npm/PyPI worm, 2026-05-11 — CI credential-theft stage

Disclosed
2026-06-09
Severity
CRITICAL
Class
Worm

DepWall returns BLOCK on install-scripts, maturity.

Regression fixture mini-shai-hulud-runner-token-theft.json · reference

DW-2026-0007

Mini Shai-Hulud (TeamPCP), npm/PyPI worm, 2026-05-11

Disclosed
2026-06-09
Severity
CRITICAL
Class
Worm

DepWall returns ASK on attestation, remote-dep.

Regression fixture mini-shai-hulud-optional-git-dep.json · reference

DW-2026-0008

npm preinstall loader whose payload lives in the tarball ([email protected], discovered 2024-12-14)

Disclosed
2026-06-02
Severity
HIGH
Class
Tarball substitution

DepWall returns ASK on install-scripts, maturity.

Regression fixture tarball-body-preinstall-loader.json · reference

DW-2026-0003

node-ipc protestware (March 2022, 'peacenotwar')

Disclosed
2022-03-15
Severity
HIGH
Class
Protestware

DepWall does not stop this. The engine returns ALLOW. Published anyway — a feed that listed only the wins would be asking for trust it has not earned.

Regression fixture node-ipc-protestware.json · reference

DW-2026-0001

ua-parser-js account compromise (Oct 2021, CISA alert)

Disclosed
2021-10-22
Severity
CRITICAL
Class
Account takeover

DepWall returns BLOCK on install-scripts.

Regression fixture ua-parser-js-hijack.json · reference

DW-2026-0002

event-stream / flatmap-stream (Nov 2018)

Disclosed
2018-11-26
Severity
CRITICAL
Class
Dependency takeover

DepWall returns BLOCK on install-scripts.

Regression fixture event-stream-flatmap-stream.json · reference

DW-2026-0004

crossenv / cross-env typosquat wave (Aug 2017)

Disclosed
2017-08-01
Severity
HIGH
Class
Typosquat

DepWall returns BLOCK on install-scripts, maturity, slopsquat.

Regression fixture crossenv-typosquat.json · reference