Latest incident:GitHub Advisory malware sweep - 2026-08-17 / 2026-08-18 batch (Sui blockchain `@mysten/*` typosquat days 4-5 continuation `sui-move-graphql`+`sui-move-rpc`+`sui-gql-core`+`bcs-core`+`bucket-protocol-sdk-v2`, Tinkoff BNPL dep-confusion tail `bnpl-blocks-independent-bnpl-search`, LEB128 encoding typosquat pair `leb128x`+`ulebkit`, generic CWE-506 boilerplate `blastradar`+`runtime-health`, PyPI `socks5901` Android `/sdcard/` Telegram-bot exfiltrator) (18 Aug 2026)
Submit an incident

Seen a supply-chain compromise we've missed?

Send us the details. Our intelligence team triages each report against the original vendor source. If it checks out, we add it to the feed within < 2 hours.

A short, factual summary. Example: “axios npm compromise (March 2026)”.

The original vendor advisory or post that reported the compromise. We'll add https:// if you leave it off - e.g. www.wiz.io/blog/some-post works.

One per line, in the form name@version. Multiple versions of the same package on separate lines.

Payload behaviour, IOCs, attribution, anything that helps us triage.

Optional. For credit / follow-up.

Optional. We only use it to reply.

We'll only contact you if we have follow-up questions about this submission.