Real-world OSS supply chain incidents mapped to risk checks

Thirty-eight distinct incidents — sourced from company postmortems, engineering blogs, maintainer statements, and developer write-ups — reveal how every category of open-source supply chain risk has materialized in production. The Codecov breach alone generated seven separate company disclosures. The 2025 chalk/debug compromise affected packages with 2 billion weekly downloads. License changes at Elastic, Redis, and HashiCorp forced hundreds of companies into costly migrations. These are not theoretical risks — they are documented engineering crises, mapped below to specific risk check codes.


Active malware and package hijacking dominate the critical category

The critical risk category has the deepest bench of real incidents, spanning account takeovers, dependency confusion, typosquatting, and manifest manipulation.

1. event-stream / flatmap-stream (November 2018)

2. ua-parser-js hijack (October 2021)

3. Codecov bash uploader compromise (April 2021)

4. eslint-scope account compromise (July 2018)

5. Dependency confusion — Alex Birsan’s research (February 2021)

6. PyTorch torchtriton dependency confusion (December 2022)

7. crossenv typosquatting (August 2017)

8. npm manifest confusion (June 2023)

9. xz utils backdoor (March 2024)

10. Ledger Connect Kit hack (December 2023)

11. Lottie Player supply chain attack (October 2024)

12. Polyfill.io domain takeover (June 2024)

13. Shai-Hulud npm worm / chalk-debug compromise (September 2025)

14. coa and rc npm packages (November 2021)

15. tj-actions/changed-files GitHub Action compromise (March 2025)


Maintainer burnout and bus factor risk have broken production at scale

The continuity-assurance category tracks single-contributor dependencies, abandoned repositories, and stale packages. These incidents prove these risks are not hypothetical.

16. left-pad removal (March 2016)

17. core-js single-maintainer crisis (2019–present)

18. colors.js / faker.js sabotage (January 2022)

19. node-ipc protestware / peacenotwar (March 2022)

20. Heartbleed / OpenSSL underfunding (April 2014)

21. Log4Shell / Log4j (December 2021)

22. Dependency rot — developer rewrite story


License compliance failures have cost companies millions in litigation and rewrites

The license-compliance and title-assurance categories cover some of the most expensive incidents, including a €900,000 judgment and a proposed $100M lawsuit.

23. Entr’ouvert v. Orange — €900K GPL violation (2011–2024)

24. Versata / XimpleWare — GPL violation discovered during litigation (2013–2015)

25. Tendermint/Cosmos — GPL contamination in Apache 2.0 project (2018)

26. BusyBox GPL enforcement — 14+ companies sued (2007–2013)

27. CoKinetic v. Panasonic Avionics — $100M+ GPL lawsuit

28. SFC v. Vizio — third-party GPL enforcement precedent (2021–present)

29. Sebastian Steck v. AVM — individual enforces LGPL (2021–2024)

31. SaaS company forced $300K AGPL rewrite

32. Google’s AGPL ban — company-wide policy


License changes forced hundreds of companies into costly migrations

33. Elastic license change — Logz.io forced to migrate entire backend (2021)

34. Bonsai — world’s first Elasticsearch host navigates license change (2021)

35. HashiCorp BSL change — OpenTofu manifesto signed by 140+ companies (2023)

36. Redis license change — CEO admits it backfired (2024–2025)

37. Black Duck OSSRA — 53% of M&A audits found license conflicts


Lockfile and install-script vectors round out the attack surface

38. Lockfile injection — demonstrated attack vector (2019)


Comprehensive incident-to-category mapping

#IncidentYearCategoriesKey Check Codes
1event-stream2018critical, security-vulnerability, continuity-assurancePACKAGE_ACTIVE_MALWARE, PACKAGE_INSTALL_SCRIPTS, SOURCE_SINGLE_CONTRIBUTOR
2ua-parser-js2021critical, security-vulnerabilityPACKAGE_ACTIVE_MALWARE, PACKAGE_INSTALL_SCRIPTS
3Codecov bash uploader2021critical, security-vulnerabilityARTIFACT_HASH_MISMATCH, PACKAGE_ACTIVE_MALWARE
4eslint-scope2018critical, security-vulnerabilityPACKAGE_ACTIVE_MALWARE, PACKAGE_INSTALL_SCRIPTS
5Dependency confusion (Birsan)2021criticalPACKAGE_NAME_MISMATCH, PACKAGE_REGISTRY_MISMATCH
6PyTorch torchtriton2022critical, security-vulnerabilityPACKAGE_NAME_MISMATCH, PACKAGE_REGISTRY_MISMATCH, PACKAGE_INSTALL_SCRIPTS
7crossenv typosquatting2017criticalPACKAGE_NAME_MISMATCH
8npm manifest confusion2023critical, title-assurancePACKAGE_REGISTRY_MISMATCH, SOURCE_MALFORMED_METADATA, PACKAGE_SOURCE_URL_MISMATCH
9xz utils backdoor2024critical, security-vulnerability, continuity-assurancePACKAGE_ACTIVE_MALWARE, SOURCE_SINGLE_CONTRIBUTOR, SOURCE_FEW_CONTRIBUTORS
10Ledger Connect Kit2023critical, security-vulnerabilityPACKAGE_ACTIVE_MALWARE, ARTIFACT_HASH_MISMATCH
11Lottie Player2024critical, security-vulnerabilityPACKAGE_ACTIVE_MALWARE, ARTIFACT_HASH_MISMATCH
12Polyfill.io2024critical, title-assurancePACKAGE_UNSAFE_SOURCE_URL, PACKAGE_SOURCE_URL_MISMATCH
13Shai-Hulud / chalk-debug2025critical, security-vulnerability, continuity-assurancePACKAGE_ACTIVE_MALWARE, PACKAGE_INSTALL_SCRIPTS, SOURCE_SINGLE_CONTRIBUTOR
14coa/rc packages2021critical, security-vulnerabilityPACKAGE_ACTIVE_MALWARE, PACKAGE_INSTALL_SCRIPTS
15tj-actions/changed-files2025critical, security-vulnerabilityPACKAGE_ACTIVE_MALWARE, PACKAGE_INSTALL_SCRIPTS
16left-pad2016continuity-assurance, security-vulnerabilitySOURCE_SINGLE_CONTRIBUTOR, PACKAGE_STALE_RELEASE
17core-js2019–nowcontinuity-assurance, security-vulnerabilitySOURCE_SINGLE_CONTRIBUTOR, SOURCE_FEW_CONTRIBUTORS
18colors.js / faker.js2022continuity-assurance, security-vulnerability, criticalSOURCE_SINGLE_CONTRIBUTOR, PACKAGE_PAST_MALWARE
19node-ipc protestware2022critical, security-vulnerability, continuity-assurancePACKAGE_ACTIVE_MALWARE, SOURCE_SINGLE_CONTRIBUTOR
20Heartbleed / OpenSSL2014continuity-assurance, security-vulnerabilitySOURCE_FEW_CONTRIBUTORS, VULN_HISTORICAL_SEVERE
21Log4Shell2021security-vulnerability, continuity-assuranceVULN_HISTORICAL_SEVERE, VULN_RECENT_FREQUENCY, SOURCE_FEW_CONTRIBUTORS
22Dependency rot (Matt March)2023continuity-assurance, security-vulnerabilityPACKAGE_STALE_RELEASE, LAST_COMMIT_OVER_A_YEAR, PACKAGE_SKEW_NOT_UPDATED
23Entr’ouvert v. Orange2011–2024license-complianceLICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT
24Versata / XimpleWare2013–2015license-compliance, title-assuranceLICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT, LICENSE_REFERENCE_MISSING_FILE, PACKAGE_NO_LICENSE
25Tendermint GPL contamination2018license-complianceLICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT, LICENSE_NOT_APPROVED
26BusyBox GPL enforcement2007–2013license-complianceLICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT, LICENSE_REFERENCE_MISSING_FILE
27CoKinetic v. Panasonic2017–2018license-complianceLICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT
28SFC v. Vizio2021–nowlicense-complianceLICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT
29Steck v. AVM2021–2024license-complianceLICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT, LICENSE_REFERENCE_MISSING_FILE
30McHardy GPL troll2012–2019license-complianceLICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT, LICENSE_MODIFIED
31AGPL rewrite ($300K)~2025license-complianceLICENSE_RESTRICTION_NETWORK_COPYLEFT
32Google AGPL banOngoinglicense-complianceLICENSE_RESTRICTION_NETWORK_COPYLEFT, LICENSE_NOT_APPROVED
33Elastic license → Logz.io2021license-compliance, title-assuranceLICENSE_RESTRICTION_COMMERCIAL, PACKAGE_LICENSE_MISMATCH
34Elastic license → Bonsai2021license-complianceLICENSE_RESTRICTION_COMMERCIAL, PACKAGE_LICENSE_MISMATCH
35HashiCorp BSL → OpenTofu2023license-complianceLICENSE_RESTRICTION_COMMERCIAL, LICENSE_NOT_APPROVED
36Redis license → Valkey fork2024license-complianceLICENSE_RESTRICTION_COMMERCIAL, LICENSE_NOT_APPROVED
37Black Duck OSSRA audits2024license-compliance, title-assurancePACKAGE_LICENSE_MISMATCH, PACKAGE_NO_LICENSE
38Lockfile injection (Snyk)2019security-vulnerabilityMissing Lockfiles, PACKAGE_INSTALL_SCRIPTS

Conclusion: every risk check code maps to real wreckage

Three patterns stand out across these 38 incidents. First, single-maintainer risk is the root cause of the majority of critical incidents — event-stream, xz utils, colors/faker, core-js, Heartbleed, and the chalk/debug worm all trace back to packages where one person held the keys. The SOURCE_SINGLE_CONTRIBUTOR and SOURCE_FEW_CONTRIBUTORS checks would have flagged every one of these before exploitation.

Second, license compliance failures are slow-motion disasters that surface during M&A, litigation, or competitive pressure. The Versata case was discovered by accident during unrelated litigation. The Entr’ouvert case took 13 years to resolve. Over half of all M&A code audits reveal license conflicts. The LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT and LICENSE_NOT_APPROVED checks address the most financially devastating category of supply chain risk.

Third, install-time script execution is the primary technical vector for turning a compromised package into a compromised system. The event-stream, eslint-scope, ua-parser-js, coa/rc, Shai-Hulud worm, and tj-actions incidents all leveraged postinstall or preinstall scripts to execute malicious code. The PACKAGE_INSTALL_SCRIPTS check flags this attack surface directly — and the npm registry itself acknowledged in 2016 that “the utility of having installation scripts is greater than the risk of worms,” a judgment the subsequent decade has thoroughly tested.