OSS Supply Chain Incidents and Competitive Landscape for OSS Risk Guard
OSS Risk Guard operates in a market defined by escalating attacks—over 60 documented supply chain incidents across every major package ecosystem—and a competitive field where no single rival matches its combination of 50-category scoring, bonded M&A reports, E&O insurance, and dollar-value risk quantification. The incidents cataloged below demonstrate that supply chain attacks have evolved from isolated typosquats to self-replicating worms affecting billions of weekly downloads, while competitors remain focused on vulnerability scanning or malware detection rather than holistic, financially quantified risk assessment. This report provides a comprehensive incident database and competitive map to support OSS Risk Guard’s positioning.
PART 1: Comprehensive supply chain security incidents
Account takeover and maintainer compromise
1. ua-parser-js (npm) — October 22, 2021 Maintainer Faisal Salman’s npm account was hijacked; malicious versions 0.7.29, 0.8.0, and 1.0.0 published with XMRig Monero cryptominer and DanaBot credential-stealing trojan. A Russian forum post had offered the account for $20,000 two weeks prior. The package had ~8 million weekly downloads and ~1,200 direct dependents with nearly 1 billion lifetime downloads. Companies using it included Facebook, Amazon, Microsoft, Google, Slack, Reddit, JetBrains, and Mozilla. CISA issued an advisory. Financial impact includes credential theft and cryptomining losses across thousands of organizations; full damages unquantified but potentially tens of millions given the breadth of corporate exposure. Risk Guard category: Account takeover detection, install script detection, cryptominer detection
2. coa and rc packages (npm) — November 4, 2021 Same threat actor (UNC3379/Mandiant tracking) hijacked both packages via compromised maintainer npm accounts. Injected obfuscated TypeScript post-install scripts downloading DanaBot trojan. Neither package had been updated in 3 years before the malicious release. coa had ~8.8 million weekly downloads (~5 million GitHub dependents); rc had ~14.2 million weekly downloads. Combined ~23 million weekly downloads. Broke React build pipelines globally. Used by Microsoft, Meta, and thousands of others. Mandiant confirmed at least one client organization was compromised via downstream package “hint.” Risk Guard category: Account takeover detection, dormant package activity anomaly, install script detection
3. eslint-scope (npm) — July 12, 2018 Attacker compromised an ESLint maintainer’s npm account via credential stuffing (password reused, no 2FA). Published eslint-scope@3.7.2 with a postinstall script exfiltrating .npmrc files (containing npm tokens) to pastebin.com, designed as a worm to steal tokens for further package compromises. eslint-scope had ~2 million weekly downloads and was a dependency of babel-eslint and webpack. ~4,500 accounts potentially had tokens exposed. npm revoked ALL tokens issued before the incident as a precaution. Risk Guard category: Account takeover detection, install script detection, credential exfiltration detection
4. rest-client gem (RubyGems) — August 2019 Attacker compromised maintainer Matthew Manning’s RubyGems account via credential stuffing. Published malicious versions 1.6.10–1.6.13 containing a backdoor that activated specifically in Rails production environments, fetched remote code from Pastebin, and exfiltrated credentials. rest-client had 113 million total downloads. Malicious versions downloaded ~1,000 times. 10+ other gems similarly affected and yanked. All Rails applications running rest-client 1.6.x in production were potentially at risk—potentially thousands of web applications. Risk Guard category: Account takeover detection, dormant maintainer activity anomaly, source-registry divergence
5. strong_password gem (RubyGems) — June 2019 Maintainer Brian McManus’s account compromised via weak/reused password; hadn’t logged into RubyGems for years. Malicious version 0.0.7 waited random time, checked for production environment, fetched payload from Pastebin, and achieved full RCE. 537 downloads of malicious version before removal. Discovered by a developer during manual dependency review at Epion Health. Limited blast radius due to small user base but demonstrated the vulnerability of dormant accounts. Risk Guard category: Account takeover detection, dormant maintainer activity anomaly, abandoned package risk
6. bootstrap-sass gem (RubyGems) — March 2019
Attacker compromised one maintainer’s RubyGems account, published malicious version 3.2.0.3 with a stealthy RCE backdoor hidden in lib/active-controller/middleware.rb that intercepted HTTP cookies for arbitrary code execution. Also yanked the legitimate version 3.2.0.2 to force upgrades. bootstrap-sass had 28 million total downloads and 12,000+ GitHub stars. ~1,670 GitHub repositories directly exposed. Maintainer admitted using a “relatively weak password.”
Risk Guard category: Account takeover detection, version yanking anomaly, source-registry divergence
7. chalk/debug phishing attack (npm) — September 8, 2025 Sophisticated adversary-in-the-middle phishing attack against npm maintainer Josh Junon via fake npmjs.help domain, capturing credentials and 2FA token. Attacker published backdoored versions of 18+ packages including chalk, debug, ansi-styles, supports-color, strip-ansi, and wrap-ansi with obfuscated cryptocurrency wallet hijacker. Combined 2+ billion weekly downloads across compromised packages. Malicious versions downloaded 2.5+ million times in ~2 hours. 70 Vercel teams identified with compromised builds. JFrog called it “most widespread supply chain attack in npm’s history.” CISA issued alert. Risk Guard category: Account takeover detection, suspicious publish pattern, obfuscated code detection
8. @solana/web3.js (npm) — December 2024 Spear-phishing targeted maintainers with publish access to @solana namespace. Malicious versions 1.95.6 and 1.95.7 published with backdoor stealing private keys via CloudFlare headers. 400,000+ weekly downloads, 3,000+ dependent projects, 51 million total downloads. $160,000+ in confirmed stolen SOL cryptocurrency. CVE-2024-54134 (CVSS 8.3). Compromised versions available ~5 hours. Risk Guard category: Account takeover detection, credential exfiltration detection, suspicious publish pattern
9. Rspack and Vant (npm) — December 2024 @rspack/core v1.1.7 and @rspack/cli v1.1.7 compromised with XMRig cryptominer via stolen npm publishing tokens. Simultaneously, Vant (Vue UI library) had 10 compromised versions published. @rspack/core: 300,000+ weekly downloads; @rspack/cli: 145,000+ weekly downloads; Vant: 41,000+ weekly. Used by Alibaba, Amazon, Discord, Microsoft. Risk Guard category: Account takeover detection, cryptominer detection, token theft detection
10. ctx package (PyPI) — May 2022 Attacker purchased the expired domain associated with the original maintainer’s email for $5, used PyPI’s password reset to take over the account, and replaced all versions with code exfiltrating environment variables (including AWS keys) to a Heroku endpoint. ~22,000 weekly downloads; ~27,000 malicious downloads during compromise; 1,000 environment variable sets collected. Combined with related PHP phpass attack, ~3 million lifetime downloads potentially affected. Risk Guard category: Account takeover via expired domain, credential exfiltration, abandoned package risk
11. PHP ctx/phpass (Packagist) — May 2022 Same attacker as PyPI ctx compromise took over PHP packages via expired domain re-registration for maintainer email, modifying packages to exfiltrate environment variables including AWS credentials. Risk Guard category: Account takeover via expired domain, credential exfiltration
Social engineering and maintainer takeover
12. event-stream / flatmap-stream (npm) — November 2018 Attacker “right9ctrl” social-engineered original maintainer Dominic Tarr (who hadn’t maintained the package since 2012) into granting npm publish rights. Added flatmap-stream dependency containing encrypted payload surgically targeted at Copay Bitcoin wallet, stealing Bitcoin from wallets with balances >100 BTC or >1,000 BCH. ~2 million weekly downloads, ~8 million downloads of malicious version in 2.5 months, ~1,600 dependent packages. BitPay/Copay was the primary target. Potentially millions in cryptocurrency theft (exact figures undisclosed). Risk Guard category: Maintainer change detection, abandoned package monitoring, single-maintainer risk, obfuscated code detection
13. XZ Utils backdoor / CVE-2024-3094 (Linux) — March 2024 Threat actor “Jia Tan” spent ~3 years building trust with sole maintainer Lasse Collin, using sock puppet accounts to pressure him into granting co-maintainer access. Introduced a sophisticated backdoor into XZ Utils 5.6.0/5.6.1 that modified OpenSSH’s sshd decryption routines to allow RCE by anyone possessing a specific Ed448 private key. CVSS 10.0. Present in virtually every Linux/macOS system. Caught before reaching stable releases by Microsoft engineer Andres Freund investigating SSH performance regression. Affected Fedora 40 beta, Debian testing, Kali Linux, Arch Linux. If undetected, could have compromised hundreds of millions of SSH-accessible servers worldwide. Widely regarded as likely state-sponsored. 35 Docker Hub images still contained the backdoor as of August 2025. Risk Guard category: Single-maintainer risk, maintainer change detection, contributor trust scoring, build reproducibility
Protestware and maintainer sabotage
14. colors.js and faker.js (npm) — January 2022 Maintainer Marak Squires deliberately sabotaged his own packages: faker.js v6.6.6 published empty; colors.js v1.4.1 included infinite loop printing zalgo text. Motivated by frustration with corporations using his free work. colors.js: 3.3 billion total downloads, 23 million weekly, ~19,000 dependents. faker.js: 272 million total downloads, 2.4 million weekly, 2,500+ dependents. Affected Amazon AWS CDK, Facebook’s Jest, Node.js Open CLI Framework. Revenera found 94% of audited customers used colors.js. Widespread CI/CD pipeline disruption costing significant developer hours across thousands of organizations. Risk Guard category: Protestware/maintainer sabotage detection, anomalous update detection, single-maintainer risk
15. node-ipc / peacenotwar (npm) — March 2022 Maintainer Brandon Nozaki Miller added destructive code to protest Russia’s Ukraine invasion. Versions 10.1.1/10.1.2 overwrote all files with ❤️ emoji for Russian/Belarusian IPs. CVE-2022-23812 (CVSS 9.8). ~1 million weekly downloads, ~761,000 users. Affected Vue.js CLI (transitive dependency) and Unity Hub. A US NGO in Belarus reportedly lost 30,000+ messages documenting human rights abuses. Russia’s Sberbank advised all Russians to stop updating software. Risk Guard category: Protestware detection, geolocation-based behavior detection, destructive payload detection
16. atomicwrites (PyPI) — July 2022 Maintainer temporarily deleted widely-used library from PyPI to protest PyPI mandating 2FA for top-1% packages. Reminiscent of left-pad. Highlighted tension between registry security mandates and volunteer maintainer autonomy. Risk Guard category: Package availability monitoring, single-maintainer risk
17. es5-ext, styled-components (npm) — March 2022 Multiple packages added post-install messages to Russian/Belarusian users protesting the Ukraine invasion. Non-destructive but unexpected behavior in dependencies. styled-components had millions of weekly downloads. Risk Guard category: Install script analysis, anomalous update detection
Package removal and availability risk
18. left-pad (npm) — March 22, 2016 Developer Azer Koçulu unpublished all 273 of his npm packages (including left-pad, an 11-line function) after a trademark dispute with Kik Messenger. 15+ million downloads prior to removal, 2.5 million in the prior month. Broke Babel, Webpack, React, React Native. Affected Facebook, PayPal, Netflix, Spotify. ~40% of modern web builds affected temporarily. npm restored the package ~2 hours later and changed policy to prevent unpublishing packages with dependents. Estimated thousands of hours of developer time and millions of dollars in disruption costs. Risk Guard category: Single-maintainer risk, package availability monitoring, dependency impact analysis
Dependency confusion attacks
19. Alex Birsan’s dependency confusion research (cross-ecosystem) — February 2021 Researcher discovered that npm, pip, and RubyGems prioritize public packages over private ones with the same name. By publishing packages matching internal company names found in leaked package.json files, Birsan gained code execution inside 35+ major companies automatically, including Apple, Microsoft, PayPal, Shopify, Netflix, Tesla, Yelp, and Uber. 75% of successful attacks used npm. Orca Security found 49% of organizations had at least one vulnerable asset. $130,000+ in bug bounties collected ($40K from Microsoft, $30K from PayPal, bounties from Apple, Shopify). Sonatype subsequently detected 63,000+ copycat packages. Risk Guard category: Dependency confusion detection, namespace confusion, private package name leak detection
20. PyTorch torchtriton (PyPI) — December 2022 Dependency confusion attack: attacker registered “torchtriton” on PyPI matching PyTorch’s internal package name. Users installing PyTorch nightly on Linux got the malicious version, which stole SSH keys, .gitconfig, passwords, and environment variables via DNS tunneling. 2,300-2,700 downloads in first week. PyTorch has ~180 million total downloads. Meta/Facebook was a primary target. Risk Guard category: Dependency confusion detection, DNS exfiltration detection
Typosquatting campaigns
21. crossenv and 39 typosquats (npm) — August 2017 User “hacktask” published ~40 packages mimicking popular packages (crossenv imitating cross-env, babelcli, jquery.js, mongose). crossenv exfiltrated environment variables on install. 679 downloads for crossenv (~50 real installs). Low impact but established the npm typosquatting attack pattern. Risk Guard category: Typosquatting detection, credential exfiltration detection
22. jeIlyfish and python3-dateutil (PyPI) — December 2019 Capital “I” substituted for lowercase “L” in jellyfish; python3-dateutil imported the malicious jeIlyfish. Stole SSH and GPG keys. jeIlyfish was live ~1 year before detection; 300-400 downloads. python3-dateutil downloaded 381 times in 2 days. Risk Guard category: Typosquatting/homoglyph detection, credential theft detection
23. colourama (PyPI) — 2017-2018 Typosquat of colorama (262M+ monthly downloads) using British spelling. Installed cryptocurrency clipboard hijacker swapping Bitcoin wallet addresses. ~55 downloads/month at detection. Spawned multiple subsequent colorama typosquats in the W4SP campaign. Risk Guard category: Typosquatting detection, crypto clipper malware detection
24. 500+ PyPI typosquatting campaign — March 2024 Automated campaign deploying 566 packages in two waves targeting requests, colorama, TensorFlow, BeautifulSoup, PyGame, and more. Each package from a unique auto-generated account. Contained encrypted zgRAT info-stealer. PyPI was forced to temporarily suspend ALL new user registrations and project creation—unprecedented. 800,000+ PyPI users potentially affected. Risk Guard category: Typosquatting detection, bulk suspicious upload detection, install script analysis
25. 451-package PyPI crypto campaign — February 2023 451 typosquatted packages published in ~1 hour targeting beautifulsoup, selenium, pytorch. Contained clipboard-replacing malware swapping cryptocurrency wallet addresses. Risk Guard category: Typosquatting detection, bulk upload detection, crypto clipper detection
26. npm 287-package blockchain C2 campaign — October 2024 287 packages impersonating Puppeteer (4M weekly downloads), Bignum.js, and crypto libraries. Novel use of Ethereum smart contracts for C2 communication, making takedowns nearly impossible. Multi-platform malware. Risk Guard category: Typosquatting detection, suspicious network communication, obfuscated code detection
27. rustdecimal / CrateDepression (Rust/crates.io) — May 2022 Typosquat of rust_decimal (3.47M+ downloads). Specifically targeted GitLab CI environments (checked GITLAB_CI env var). Downloaded Mythic framework “Poseidon” agent. Attacker impersonated a known Rust developer. <500 real downloads. Risk Guard category: Typosquatting detection, CI pipeline targeting, developer impersonation
28. BoltDB typosquat (Go) — November 2021, discovered February 2025
github.com/boltdb-go/bolt typosquatting legitimate github.com/boltdb/bolt. Contained RCE backdoor. First documented exploit of Go Module Mirror’s indefinite caching—after caching, attacker modified Git tags to point to benign code, but Mirror continued serving malicious cached version. Persisted 3+ years undetected. Legitimate BoltDB depended on by 8,367 packages.
Risk Guard category: Typosquatting detection, cache poisoning detection, archived dependency risk
29. Maven Jackson typosquatting (Java) — 2025
Malicious package under org.fasterxml.jackson.core mimicking legitimate com.fasterxml.jackson.core. TLD prefix swap attack with multi-staged payload, encrypted C2, platform-specific executables. First sophisticated malware detected on Maven Central. Jackson has billions of downloads.
Risk Guard category: Typosquatting/namespace confusion, obfuscated code detection
30. @typescript_eslinter/eslint scope spoofing (npm) — November 2024 Fake scoped package mimicking @typescript-eslint. Also @types-node spoofing @types/node. Hundreds of downloads daily. Risk Guard category: Namespace/scope spoofing detection, typosquatting detection
31. NuGet malware campaigns (.NET) — 2023-2025 Multiple campaigns: 700+ malicious packages exploiting MSBuild integrations (August 2023); SeroXen RAT distribution; time-bomb packages with trigger dates set for 2027-2028. Used homoglyphs and IL weaving to inject malicious code. NuGet hosts packages with billions of total downloads. Risk Guard category: Typosquatting detection, build integration exploitation, obfuscated code detection
32. MUT-8694 cross-ecosystem campaign (npm + PyPI) — October 2024 Datadog-tracked threat cluster publishing typosquats across both npm and PyPI downloading external Windows binaries. Persistent actor using numerous packages and multiple accounts. Risk Guard category: Typosquatting detection, binary execution detection, cross-ecosystem monitoring
33. 241 cryptominer typosquats (npm + PyPI) — August 2022 241+ packages typosquatting React, argparse, AIOHTTP. Downloaded Bash scripts on Linux to run XMRig Monero miners. Risk Guard category: Typosquatting detection, cryptominer detection, install script analysis
Malware injection and info-stealer campaigns
34. W4SP Stealer campaign (PyPI) — July 2022 – March 2023+ Persistent multi-wave campaign deploying W4SP Stealer via dozens of malicious PyPI packages (pyquest, ultrarequests, ascii2text, etc.). Stole Discord tokens, browser credentials, crypto wallets, credit card data. Techniques evolved to include steganography. 5,700+ downloads in initial wave. Hundreds of malicious packages total. Copycat attacks emerged after code leaked. Risk Guard category: Typosquatting detection, malicious install script, info-stealer detection, obfuscated code detection
35. ESET 116-package cluster (PyPI) — May–December 2023 116 packages across 53 projects delivering backdoors and cryptocurrency clipboard monitors. 10,000+ total downloads, ~80 downloads/day. Used three distinct injection techniques. Risk Guard category: Obfuscated code detection, crypto clipper detection, bulk upload detection
36. “Cool Package” / pytoileur campaign (PyPI) — 2023-2024 Persistent campaign publishing packages described as “Cool package” with whitespace-hidden base64 payloads in setup.py. Later packages targeted AI developers (e.g., “gpt-requests”). Included keylogging, webcam access, screenshot capture. Risk Guard category: Obfuscated setup script detection, trojan downloader detection
37. requesys ransomware (PyPI) — 2022 Typosquat of requests containing actual ransomware that encrypted files on Windows. One of the most destructive PyPI malware payloads discovered. Risk Guard category: Typosquatting detection, ransomware detection, install script analysis
38. pymafka Cobalt Strike (PyPI) — May 2022 Typosquat of PyKafka delivering Cobalt Strike beacons to Windows, macOS, and Linux. ~300 downloads. Cobalt Strike indicates APT-level targeting. Risk Guard category: Typosquatting detection, advanced persistent threat tool detection
39. 2025 cloud credential theft campaign (PyPI) — November 2023 – March 2025 20 packages stealing AWS, Alibaba Cloud, and Tencent Cloud tokens. Three packages were dependencies of popular GitHub project accesskey_tools (519 stars), creating transitive infection. 14,100+ cumulative downloads. Risk Guard category: Credential theft detection, transitive dependency infection, combosquatting detection
40. JarkaStealer AI chatbot lure (PyPI) — November 2023-2024 Packages using functional AI chatbot tools as lures to distribute JarkaStealer. Undetected for nearly a year. 1,700+ downloads across 30+ countries. Risk Guard category: Social engineering lure detection, info-stealer detection
41. Fortinet “WS” campaign (PyPI) — 2023-2024 Single prolific malware author deploying WhiteSnake PE malware on Windows and Python info-stealers on Linux. 2,000+ estimated victims. Risk Guard category: Info-stealer detection, cross-platform malware detection
42. getcookies backdoor chain (npm) — May 2018 Sophisticated backdoor hidden in nested dependency chain: mailparser → http-fetch-cookies → express-cookies → getcookies. Backdoor parsed HTTP headers for RCE commands. mailparser had ~64,000 weekly downloads. Caught before widespread exploitation. Risk Guard category: Backdoor via dependency chain detection, suspicious new package detection
43. RubyGems mass typosquatting (2019-2025) Multiple campaigns including: Fastlane plugin impersonators (June 2025), 60+ malicious gems targeting South Korean marketers (2025), ddtracer primed repository attack (2023). Supply chain attacks in RubyGems increased 600%+ between 2020-2021. Risk Guard category: Typosquatting detection, brandjacking detection
Self-replicating worms and advanced attacks
44. Shai-Hulud worm (npm) — September–November 2025 Self-replicating worm compromising 500+ packages (first wave), then 700+ packages (second wave including 25,000+ GitHub repos across 350+ users). Harvested GitHub PATs, npm tokens, AWS/GCP/Azure keys. Used stolen tokens to automatically infect other packages. Destructive failsafe: if malware lost C2 access, would attempt to destroy user’s home directory. Affected CrowdStrike packages, DuckDB, Zapier, ENS Domains, PostHog, Postman. Some packages present in ~27% of cloud environments (Wiz scan). CISA issued formal advisory. Risk Guard category: Self-propagating malware detection, account takeover detection, install script detection, credential theft
45. Nx / s1ngularity (npm) — August 2025 Attackers stole npm publishing token via vulnerable GitHub Actions workflow. Published malicious Nx versions (20.9.0–21.8.0) with telemetry.js harvesting crypto wallets, GitHub/npm tokens, SSH keys. First known attack to weaponize AI CLI tools—checked for Claude, Gemini, Q tools. Nx: ~3.5 million weekly downloads. 1,346+ s1ngularity repositories created; 2,349 secrets leaked; 1,000+ valid GitHub tokens; 5,500+ private repos made public. Risk Guard category: CI/CD pipeline vulnerability, token theft detection, install script analysis, AI tool exploitation
46. @0xengine/xmlrpc year-long cryptominer (npm) — October 2023 – November 2024 Started as legitimate XML-RPC implementation, received 16 updates over a year, then evolved to include cryptomining and data theft. Stole SSH keys every 12 hours. Evaded detection over a year through gradual escalation. 68 compromised systems. Risk Guard category: Behavioral drift detection, cryptominer detection, long-term monitoring
CI/CD and build pipeline compromise
47. Codecov supply chain attack — January–April 2021 Attackers exploited a Docker image creation error to modify Codecov’s Bash Uploader script, adding a line exfiltrating ALL environment variables from CI environments to attacker IPs. Undetected ~2 months. Codecov claimed 29,000+ enterprise customers including Atlassian, Kubernetes, Python, Node.js, Ansible. Downstream impacts: Twitch (private repos cloned), HashiCorp (GPG signing key exposed), Monday.com, Mercari. FBI launched federal investigation. Compared to SolarWinds in scope. Risk Guard category: Build/CI pipeline compromise, integrity verification, secret exfiltration detection
48. SolarWinds / Sunburst — December 2020 APT29 (Russian SVR) compromised SolarWinds’ build environment, injecting “Sunburst” malware into Orion platform updates. 18,000+ organizations installed compromised updates; ~40 actively targeted including US Treasury, Commerce, State Department, DOE, FireEye, Microsoft, Intel, Cisco, Deloitte. Average cost: 11% of annual revenue (~$12 million per company). SolarWinds spent $40 million in first 9 months. Insured losses: $90 million. Led to Biden’s Executive Order on Cybersecurity and industry-wide SBOM adoption push. Risk Guard category: Build infrastructure compromise, supply chain integrity, SBOM analysis
49. Ultralytics YOLO (PyPI) — December 2024 Attackers exploited GitHub Actions script injection to poison the build cache and inject XMRig cryptominer. ~60 million total downloads, found in ~10% of cloud environments (Wiz). 33,000+ GitHub stars. Four malicious versions available for hours. Affected downstream packages including ComfyUI Impact Pack. Google Colab flagged accounts for crypto mining. Risk Guard category: CI/CD pipeline compromise, build environment injection, cryptominer detection
50. GhostAction campaign (npm/PyPI) — September 2025 327 GitHub users compromised across 817 repositories. Malicious workflows exfiltrated 3,325 secrets including PyPI, npm, and DockerHub tokens. PyPI tokens used to attempt publishing malicious packages. Risk Guard category: CI/CD compromise, token theft, workflow injection
51. eslint-config-prettier (npm) — 2025 Phishing attack pushed poisoned versions directly to npm without source code changes. 14,000+ packages declared it as direct dependency. Automated systems like Dependabot auto-merged malicious updates. Risk Guard category: Account compromise, source-registry divergence detection
Domain and project acquisition attacks
52. Polyfill.io (JavaScript/CDN) — June 2024 Chinese company Funnull acquired the polyfill.io domain in February 2024 from original developer Andrew Betts (who warned users to remove it). By June, cdn.polyfill.io injected malicious JavaScript redirecting mobile users to gambling/scam sites. 100,000–110,000+ websites directly affected; 384,773 hosts still embedding the script as of July 2. Affected JSTOR, Intuit, World Economic Forum, Hulu, Mercedes-Benz, WarnerBros. 50%+ of enterprises impacted. Google warned advertisers. Cloudflare and Fastly created emergency mirrors. Risk Guard category: Ownership change monitoring, domain/project acquisition detection, CDN integrity
53. MavenGate (Java/Maven) — 2024 Oversecured found that 18%+ of Maven dependencies could be intercepted via abandoned domain purchases. Attack exploits how Maven resolves dependencies across multiple repositories. Theoretical massive blast radius affecting all Maven-based technologies. Risk Guard category: Abandoned dependency hijacking, domain expiry monitoring
Critical vulnerabilities in under-maintained projects
54. Log4Shell / CVE-2021-44228 (Java/Maven) — December 2021 Critical RCE in Log4j’s JNDI lookup feature. Any logged user input could trigger remote code execution. CVSS 10.0. Estimated to affect hundreds of millions of devices. 93% of cloud enterprise environments were vulnerable. Major affected vendors: Apple, Amazon, Google, Microsoft, Cisco, VMware, and thousands more. CISA mobilized thousands of security professionals. Active exploitation within hours including by nation-state actors and ransomware groups. CISQ estimated $2.4 trillion in overall cost of poor software quality (Log4Shell a key factor). The vulnerability was maintained by volunteers. Log4j downloaded millions of times monthly. Risk Guard category: Known vulnerability (critical), transitive dependency risk, under-maintained critical project, community health
55. Heartbleed / CVE-2014-0160 (OpenSSL) — April 2014 Buffer over-read in OpenSSL’s TLS heartbeat extension exposing up to 64KB of server memory per request (private keys, passwords, session cookies). 17% of all SSL web servers (~500,000) vulnerable. OpenSSL powered 66% of all web servers. Canada Revenue Agency breached (900 SINs stolen). Estimated remediation cost: $500 million+. Only 14% of affected sites completed all remediation steps. At discovery, OpenSSL was maintained by a handful of volunteers, only ONE full-time, with ~$2,000/year in donations. Led to Linux Foundation’s Core Infrastructure Initiative ($5.5M raised). Risk Guard category: Single-maintainer/underfunded project risk, community health, vulnerability scanning
56. Spring4Shell / CVE-2022-22965 (Java/Maven) — March 2022 Critical RCE in Spring Framework (CVSS 9.8). Active exploitation within 24 hours including Mirai botnet deployment. Spring is the most widely-used Java web framework globally. CISA added to Known Exploited Vulnerabilities catalog. Risk Guard category: Known vulnerability (critical), framework-level risk
57. Text4Shell / CVE-2022-42889 (Java/Maven) — October 2022 RCE in Apache Commons Text (CVSS 9.8). Exploitation requires specific usage patterns. Active scanning from Russian and Chinese IP space. Risk Guard category: Known vulnerability (critical), transitive dependency risk
58. Lodash prototype pollution (npm) — 2018-2020 Multiple prototype pollution vulnerabilities (CVE-2019-10744 CVSS 9.1). ~50 million weekly downloads, 4+ million dependent GitHub projects. Affected virtually every major Node.js application. Risk Guard category: Known vulnerability, unpatched dependency risk
59. PAC-Resolver SSRF/RCE (npm) — September 2021 Critical RCE in pac-resolver via unsafe Node.js VM module (CVSS 8.1). ~3 million weekly downloads. proxy-agent used in AWS CDK, Firebase CLI, and enterprise applications. Risk Guard category: Known vulnerability (RCE), transitive dependency risk
60. node-netmask SSRF (npm) — March 2021 Improper IP parsing enabling SSRF/RFI/LFI bypasses (CVSS 9.1). ~3 million weekly downloads, 238+ million total downloads, ~278,000 dependent repositories. Risk Guard category: Known vulnerability (SSRF), critical library flaw
Malicious maintainer / long-con attacks
61. aiocpa backdoor (PyPI) — September–November 2024 Attacker published a genuinely functional Crypto Pay API client, built a user base over months, then injected credential-stealing code in version 0.1.13. The GitHub source remained clean—only the PyPI-published version contained malware. 12,100 total downloads. Novel “long game” approach. Risk Guard category: Source-binary mismatch detection, maintainer-initiated backdoor, obfuscated code
62. LottieFiles lottie-player (npm) — October 2024 Popular animation library compromised via credential theft. Malicious code stole cryptocurrency via wallet drainer. Widely used in web applications. Risk Guard category: Account compromise, crypto wallet drainer detection
63. num2words (PyPI) — July 2025 Suspicious version published without corresponding GitHub tag or commit. Linked to “Scavenger” threat actor. Quickly removed by PyPI. Risk Guard category: Source-registry mismatch, maintainer account compromise
License violation lawsuits and compliance incidents
64. FSF v. Cisco/Linksys — 2008-2009 FSF sued Cisco for distributing GPL/LGPL programs (GCC, GNU Binutils, glibc) in Linksys routers without compliance. Settlement: Cisco appointed internal Free Software Compliance Officer. Undisclosed financial settlement. Demonstrates compliance risk in consumer electronics. Risk Guard category: GPL/LGPL license compliance scanning
65. Artifex v. Hancom — 2016-2017 Hancom incorporated Ghostscript (GPL v3/AGPL) into Hancom Office without paying for commercial license or complying with GPL. Hancom reported $86.3M revenue in 2015. Landmark ruling: court found GPL is an enforceable contract and commercial license fees can be basis for damages. Settled confidentially. Risk Guard category: GPL/AGPL violation detection, dual-licensing detection
66. Entr’ouvert v. Orange S.A. — 2011-2024 Orange integrated GPL v2-licensed Lasso library (57% of source code) into a French government portal without compliance. Paris Court of Appeal: €500,000 compensatory + €150,000 moral damages + €150,000 disgorgement = €800,000+. Highest known monetary award in a GPL case. Classified as “counterfeiting.” Risk Guard category: GPL violation detection, copyleft enforcement
67. SFC v. Vizio — 2021-pending SFC sued Vizio for GPL/LGPL violations in SmartCast TVs. Novel third-party beneficiary theory: SFC is not a copyright holder but claims standing as a user. If SFC prevails, could dramatically expand who can enforce open source licenses. Pending trial. Risk Guard category: GPL/LGPL violation detection
68. CoKinetic v. Panasonic Avionics — pending GPL v2 violation allegations in in-flight entertainment systems. Seeking over $100 million in damages. Demonstrates enormous financial stakes of GPL non-compliance in specialized industries. Risk Guard category: GPL violation detection
69. BusyBox GPL enforcement campaign — 2007-2013 Serial enforcement against 14+ companies (Best Buy, Samsung, Westinghouse, Verizon). Multiple settlements. Westinghouse received default judgment. Established pattern of serial GPL enforcement in US courts. Risk Guard category: GPL violation detection
70. Christoph Hellwig/SFC v. AVM — 2023-2024 Individual Linux kernel developer sued German router maker AVM for LGPL violation. Court ruled in Hellwig’s favor. Demonstrates individual developers can enforce OSS licenses. Risk Guard category: LGPL violation detection
PART 2: Competitive landscape analysis
The market is converging but no one matches Risk Guard’s breadth
The software supply chain security market reached $2.16 billion in 2025 and is projected to hit $3.27 billion by 2034 (10.9% CAGR). Supply chain attack costs are projected to triple from $46 billion (2023) to $138 billion by 2031. GigaOm’s October 2025 Radar assessed 25 leading solutions, finding the market shifting from individual scanners to integrated platforms. Despite this consolidation, no competitor combines OSS Risk Guard’s 50-category scoring, E&O insurance warranty, bonded M&A reports with dollar-value quantification, MCP server for AI agents, and air-gapped deployment.
Tier 1: Most similar competitors
Socket (socket.dev) — $65M raised, ~$4.2M revenue, 400% revenue growth (2024). Founded 2020 by Feross Aboukhadijeh. Series B led by a16z. Acquired Coana (reachability analysis) April 2025. Protects 7,500+ organizations, 300,000+ GitHub repos. Socket is the closest competitor in philosophy—it performs deep behavioral analysis of packages across 70+ risk signal types rather than just matching CVEs. It detects typosquatting, obfuscated code, data exfiltration, and install script abuse proactively. Free tier available. Per-developer pricing ($8/user/month). Notable customers include Anthropic and Replit. Strengths vs. Risk Guard: superior real-time malware detection (first to catch many attacks including Shai-Hulud), larger free-tier adoption, strong developer UX, AI-powered behavioral analysis. Weaknesses vs. Risk Guard: no 50-category scoring taxonomy, no policy engine with blocking thresholds, no MCP server for AI, no air-gapped deployment, no E&O insurance, no bonded M&A reports, no dollar-value risk quantification, does not target M&A/PE buyers at all.
Endor Labs — $188M raised, ~$13.6M ARR (Sep 2025), 225% YoY revenue growth. Founded 2021 by Varun Badhwar (ex-Palo Alto Networks). Series B $93M (April 2025). Endor Labs is the most technically ambitious competitor, offering dependency lifecycle management with deep reachability analysis, graph-based analysis across 4.5M+ OSS projects, AI-powered auto-remediation agents, and integrated SAST+SCA via Opengrep. Mentions MCP server integration for AI workflow security. Notable customers: OpenAI, Rubrik, Paylocity. Strengths vs. Risk Guard: much larger funding/team, deep reachability analysis engine, GitHub Advanced Security partnership, agentic AI capabilities. Weaknesses vs. Risk Guard: no M&A/PE due diligence focus, no E&O insurance, no air-gapped deployment mentioned, no dollar-value risk quantification, no bonded reports, broader AppSec focus dilutes supply chain risk depth.
Stacklok / Trusty (now Stacklok Insight) — $17.5M Series A (May 2023). Founded 2022 by Craig McLuckie (Kubernetes co-creator) and Luke Hinds (Sigstore creator). Offers package trustworthiness scoring on a 0-10 scale, Trust Graph mapping contributor-project relationships, Sigstore-based provenance verification, typosquatting detection, and free GitHub Action. Supports npm, PyPI, Maven, Cargo, Go. Donated Minder policy platform to OpenSSF. Strengths: free/open-source, novel Trust Graph concept, Sigstore provenance. Weaknesses: much smaller scale, fewer scoring dimensions than 50 categories, no enterprise deployment, no policy engine depth, no M&A focus, no insurance/warranty, no dollar-value quantification. Early-stage lightweight developer tool rather than enterprise platform.
Lineaje — $27M raised, $20M Series A (July 2024). SBOM-centric approach managing 150,000+ SBOMs. Deep binary analysis revealing hidden components. “Gold Open Source” curated packages. Third Party Risk Manager product specifically for vendor risk—the closest overlap with Risk Guard’s M&A use case. Won $1.8M US Air Force contract (July 2025). Notable customers: Veritas, Pure Storage, US Air Force. Strengths: strong government/defense traction, deep binary analysis, TPRM product partially overlaps M&A use case. Weaknesses: no comprehensive 50-category scoring, no E&O insurance, no bonded reports, no dollar-value quantification, smaller scale, less developer-focused.
Tier 2: Established players with partial overlap
Snyk — $1.32 billion raised, ~$408M revenue (2025), ~$7.4B valuation. The market leader in developer security. Broadest platform: SCA + SAST + Container + IaC + Cloud + AI security. 2.5M+ developers, 4,500+ customers (Google, Intuit, Salesforce). Launched AI Trust Platform in 2025. Pricing starts ~$25-50/dev/month. Strengths: massively larger platform and brand, deepest funding, strongest ecosystem. Weaknesses: vulnerability-focused rather than holistic risk, no 50-category scoring, no MCP server, no air-gapped deployment, no E&O insurance, no M&A due diligence, no dollar-value quantification. Expanding into cloud security dilutes supply chain focus.
Sonatype (Nexus) — $148M+ raised, acquired by Vista Equity Partners (2019). Claims 70% of Fortune 100 as customers. Unique combination of Nexus Repository (artifact management) + Lifecycle (SCA) + Firewall (malicious package blocking at ingestion). Air-gapped deployment available—shared capability with Risk Guard. Policy engine with flexible rules. Supports 50+ languages. Strengths: repository management is unique differentiator, Nexus Firewall blocks threats at ingestion, air-gapped deployment, Fortune 100 penetration, automated “Golden Fixes.” Weaknesses: no 50-category scoring breadth, no MCP server, no E&O insurance, no bonded M&A reports, no dollar-value quantification, architecture criticized as “archaic” by some users.
Black Duck (formerly Synopsys SIG) — Acquired by Clearlake Capital + Francisco Partners for up to $2.1B (October 2024). KnowledgeBase of 8.7M+ OSS projects, 15B+ code files—largest in industry. 7 consecutive years as Gartner Magic Quadrant Leader for AST. The industry standard for M&A open source audits, performing hundreds of transactions per year. 2025 OSSRA Report: 85% of M&A transactions had license conflicts, 96% had unpatched vulnerabilities. Audit services priced at $30K-$100K+ per codebase. Strengths: largest knowledge base, established M&A practice with decades of track record, comprehensive AST portfolio, massive PE backing, deep license compliance. Weaknesses: reports are qualitative, not bonded or dollar-value quantified, no E&O insurance on reports, no MCP server, no 50-category scoring, M&A audits are point-in-time and human-driven (expensive, not continuous), heavier setup, PE ownership may prioritize cost optimization. Black Duck is the primary incumbent competitor for M&A use case but addresses it differently—manual audits vs. Risk Guard’s automated bonded reports.
Mend (formerly WhiteSource) — $124M raised. Strong license compliance. AI-native platform with all products (SCA + SAST + Container + AI + Renovate dependency updater) included in one price. Mend Renovate is industry-leading for automated dependency updates. Customers: Microsoft, IBM, Siemens, KPMG. Strengths: all-in-one pricing, Mend Renovate unique capability, AI-native features, 200+ language support. Weaknesses: no 50-category scoring, no MCP server, SaaS-only (no air-gapped), no E&O insurance, no M&A due diligence, no dollar-value quantification. Brand suffered from WhiteSource → Mend rebrand.
Tier 3: Specialized or complementary tools
Phylum (acquired by Veracode January 2025 for undisclosed price) — Was the pure-play malware detection specialist. Automated analysis pipeline processing ~21K packages/day. Identified ~500K malicious packages. Technology now integrated into Veracode’s SCA. No longer independent.
Semgrep Supply Chain — $193M raised, $100M Series D (Feb 2025). Strong SAST + SCA combination with reachability analysis (claims 98% false positive reduction). Powers GitLab’s SCA. Customers: Snowflake, Plaid, Lyft. Focused on code vulnerabilities rather than holistic risk assessment.
JFrog Xray — Public company (NASDAQ: FROG, ~$5-7B market cap, $400M+ revenue). Binary-level artifact scanning integrated with JFrog Artifactory. Requires JFrog ecosystem. Not focused on holistic risk scoring.
Chainguard — $892M raised, $3.5B valuation. Largest funding in the space. But fundamentally different: eliminates vulnerabilities by rebuilding container images daily from source. Complementary to Risk Guard rather than competitive. Secures what you deploy; Risk Guard evaluates what you should use.
OpenSSF Scorecard — Free, open-source project scoring with ~20 checks. Widely adopted as baseline. Not a commercial product—no policy engine, enforcement, enterprise features, or M&A capability.
Deps.dev (Google) — Free public dependency insights service. Research tool, not a security platform. No enforcement, policy, or enterprise features.
Aqua Security / Trivy — Trivy is the most widely adopted open-source scanner. Container/K8s focused. Not a risk assessment platform.
Legit Security — $74M raised. ASPM platform spanning SDLC security. Mentions MCP server integration. Broader SDLC focus dilutes OSS-specific depth.
Kusari — $8M raised. Very early stage. Novel GUAC knowledge graph approach (OpenSSF incubating). Financial services pedigree.
Seal Security — $20.4M raised. Remediation-only (not detection). LLM-powered patch generation. Complementary.
Other notable entrants: Aikido Security (Belgium, all-in-one with SafeChain malware detection), Xygeni (full-stack SDLC protection), Scribe Security (SBOM management and attestation).
Five capabilities no competitor replicates
The competitive analysis reveals five OSS Risk Guard capabilities that exist nowhere else in the market:
-
E&O insurance warranty on reports stands alone as a commercial innovation. No competitor—from $65M Socket to $2.1B Black Duck—offers insured risk assessments. This transforms a security report into a financial instrument.
-
Bonded M&A due diligence reports with dollar-value risk quantification address a gap that Black Duck has dominated qualitatively for decades but never financially. Black Duck’s OSSRA reports catalog risks; Risk Guard quantifies them in dollars. For PE firms evaluating acquisitions, this difference determines whether open source risk appears in the financial model or remains an IT footnote.
-
MCP server for AI agent integration positions Risk Guard for the emerging agentic AI workflow. While Endor Labs and Legit Security discuss MCP in the context of securing MCP servers, Risk Guard’s approach makes risk data consumable by AI agents—a fundamentally different and forward-looking architecture.
-
Air-gapped enterprise deployment combined with M&A focus serves defense, government, and regulated-industry buyers that SaaS-only competitors cannot reach. Only Sonatype shares air-gapped capability, but lacks the M&A and insurance features.
-
50 scoring categories spanning continuity, title, legal, and security represent the broadest risk taxonomy in the market. OpenSSF Scorecard has ~20 checks; Socket has 70+ detection types (different concept—behavioral signals, not scoring categories); most competitors focus narrowly on CVEs and licenses.
Where competitors hold advantages
Risk Guard faces legitimate competitive pressure on several fronts. Socket and Phylum/Veracode lead in real-time malware detection—Socket was first to identify several major 2025 attacks. Snyk’s $408M revenue and 2.5M developers create massive distribution and ecosystem advantages. Black Duck’s decades of M&A audit history means PE firms already have established relationships and trust. Chainguard’s $892M in funding and $3.5B valuation demonstrate investor appetite for supply chain security. Endor Labs’ reachability analysis solves the false-positive problem that plagues traditional SCA. Risk Guard’s differentiation is strongest when the buyer values financial quantification and insurance—a positioning that fits M&A and PE buyers better than developer teams, where Socket and Snyk dominate.
Competitive positioning summary
| Capability | Socket | Snyk | Sonatype | Black Duck | Endor Labs | Mend | Risk Guard |
|---|---|---|---|---|---|---|---|
| Multi-category scoring | Partial | ❌ | ❌ | ❌ | Partial | ❌ | 50 categories |
| Policy engine | Limited | Limited | ✅ | ✅ | ✅ | ✅ | ✅ |
| MCP server for AI | ❌ | ❌ | ❌ | ❌ | Partial | ❌ | ✅ |
| Air-gapped deployment | ❌ | ❌ | ✅ | ❌ | ❌ | ❌ | ✅ |
| E&O insurance | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ |
| Bonded M&A reports | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ |
| Dollar-value risk | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ |
| M&A due diligence | ❌ | ❌ | Partial | Core | ❌ | ❌ | ✅ |
| Malware detection | Best | Limited | Strong | Limited | Limited | Strong | ✅ |
| Maintainer health | Limited | Limited | Limited | Limited | Partial | ❌ | Deep |
| License compliance | ✅ | ✅ | ✅ | Best | ✅ | Strong | ✅ |
| Total funding | $65M | $1.32B | $148M+PE | $2.1B PE | $188M | $124M | — |
Conclusion
The incident database demonstrates that supply chain attacks have grown from novelty (crossenv’s 679 downloads in 2017) to existential threat (Shai-Hulud compromising 27% of scanned cloud environments in 2025). Every one of the 70 incidents maps to at least one of Risk Guard’s 50 scoring categories—account takeover, typosquatting, install script detection, single-maintainer risk, license compliance, abandoned package monitoring, or dependency confusion. The most destructive incidents (XZ Utils, Log4Shell, Heartbleed) were specifically enabled by under-maintained projects with single-maintainer risk—a category most competitors ignore entirely.
In the competitive landscape, Risk Guard occupies a unique intersection: the only tool that simultaneously scores holistic risk across 50 dimensions, quantifies that risk in dollar terms, backs reports with insurance, and serves both developer CI workflows and M&A due diligence. Black Duck dominates the established M&A audit market but with qualitative, point-in-time, human-driven assessments—not automated, bonded, dollar-quantified reports. Socket leads malware detection but doesn’t address business risk or M&A buyers. The strategic moat is clearest in the M&A/PE use case, where financial quantification and insurance convert open source risk from an IT concern into a deal-shaping financial instrument.