The Weekly Dependency Threat Report: 2026-08-22
This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. matrixflow-js (npm) * Package: https://www.npmjs.com/package/matrixflow-js * Severity: critical * Affected versions: 3.2.1 * Downloads: 1504353 * First seen: 19 August 2026 at 09:21 UTC [email protected] is a typosquat/repackage of ml-matrix (the UMD global is mlMatrix; homepage matrixflow-js.github.io does not correspond to the real ml-matrix project). Its mai
Read more
24 August 2026
11 min read