Advisories
Real supply-chain incidents, and what DepWall's engine actually
returns for each one.
Every verdict below is recomputed by replaying the incident
through the live signals engine when this page is generated. None of them is a
remembered claim, which is why a row can say the engine missed
something — and some do.
These are documents. DepWall's client does not read this page,
and nothing here changes a verdict on your machine: a feed the scanner trusted
would be a way to attack the scanner.
Generated 2026-08-08 from 9 incidents in the regression corpus.
DepWall's verdict is recomputed, not recorded. Sorted newest first.
| ID |
Disclosed |
Severity |
Class |
Incident |
DepWall |
| DW-2026-0009 |
2026-08-04 |
CRITICAL |
Attested build, poisoned source |
keyv/cacheable maintainer compromise (Aug 2026) — malicious release carrying valid npm provenance |
BLOCK |
| DW-2026-0005 |
2026-06-09 |
CRITICAL |
Worm |
Mini Shai-Hulud (TeamPCP), 2026-05-11 — dead-man-switch / wiper stage |
BLOCK |
| DW-2026-0006 |
2026-06-09 |
CRITICAL |
Worm |
Mini Shai-Hulud (TeamPCP), npm/PyPI worm, 2026-05-11 — CI credential-theft stage |
BLOCK |
| DW-2026-0007 |
2026-06-09 |
CRITICAL |
Worm |
Mini Shai-Hulud (TeamPCP), npm/PyPI worm, 2026-05-11 |
ASK |
| DW-2026-0008 |
2026-06-02 |
HIGH |
Tarball substitution |
npm preinstall loader whose payload lives in the tarball ([email protected], discovered 2024-12-14) |
ASK |
| DW-2026-0003 |
2022-03-15 |
HIGH |
Protestware |
node-ipc protestware (March 2022, 'peacenotwar') |
ALLOW missed |
| DW-2026-0001 |
2021-10-22 |
CRITICAL |
Account takeover |
ua-parser-js account compromise (Oct 2021, CISA alert) |
BLOCK |
| DW-2026-0002 |
2018-11-26 |
CRITICAL |
Dependency takeover |
event-stream / flatmap-stream (Nov 2018) |
BLOCK |
| DW-2026-0004 |
2017-08-01 |
HIGH |
Typosquat |
crossenv / cross-env typosquat wave (Aug 2017) |
BLOCK |
Detail
keyv/cacheable maintainer compromise (Aug 2026) — malicious release carrying valid npm provenance
- Disclosed
- 2026-08-04
- Severity
- CRITICAL
- Class
- Attested build, poisoned source
DepWall returns BLOCK on attestation, install-scripts, known-malicious.
Regression fixture keyv-provenance-signed-compromise.json · reference
Mini Shai-Hulud (TeamPCP), 2026-05-11 — dead-man-switch / wiper stage
- Disclosed
- 2026-06-09
- Severity
- CRITICAL
- Class
- Worm
DepWall returns BLOCK on install-scripts.
Regression fixture mini-shai-hulud-wiper.json · reference
Mini Shai-Hulud (TeamPCP), npm/PyPI worm, 2026-05-11 — CI credential-theft stage
- Disclosed
- 2026-06-09
- Severity
- CRITICAL
- Class
- Worm
DepWall returns BLOCK on install-scripts, maturity.
Regression fixture mini-shai-hulud-runner-token-theft.json · reference
Mini Shai-Hulud (TeamPCP), npm/PyPI worm, 2026-05-11
- Disclosed
- 2026-06-09
- Severity
- CRITICAL
- Class
- Worm
DepWall returns ASK on attestation, remote-dep.
Regression fixture mini-shai-hulud-optional-git-dep.json · reference
npm preinstall loader whose payload lives in the tarball ([email protected], discovered 2024-12-14)
- Disclosed
- 2026-06-02
- Severity
- HIGH
- Class
- Tarball substitution
DepWall returns ASK on install-scripts, maturity.
Regression fixture tarball-body-preinstall-loader.json · reference
node-ipc protestware (March 2022, 'peacenotwar')
- Disclosed
- 2022-03-15
- Severity
- HIGH
- Class
- Protestware
DepWall does not stop this. The engine returns
ALLOW.
Published anyway — a feed that listed only the wins would be asking for trust it has not earned.
Regression fixture node-ipc-protestware.json · reference
ua-parser-js account compromise (Oct 2021, CISA alert)
- Disclosed
- 2021-10-22
- Severity
- CRITICAL
- Class
- Account takeover
DepWall returns BLOCK on install-scripts.
Regression fixture ua-parser-js-hijack.json · reference
event-stream / flatmap-stream (Nov 2018)
- Disclosed
- 2018-11-26
- Severity
- CRITICAL
- Class
- Dependency takeover
DepWall returns BLOCK on install-scripts.
Regression fixture event-stream-flatmap-stream.json · reference
crossenv / cross-env typosquat wave (Aug 2017)
- Disclosed
- 2017-08-01
- Severity
- HIGH
- Class
- Typosquat
DepWall returns BLOCK on install-scripts, maturity, slopsquat.
Regression fixture crossenv-typosquat.json · reference