Real-world OSS supply chain incidents mapped to risk checks
Thirty-eight distinct incidents — sourced from company postmortems, engineering blogs, maintainer statements, and developer write-ups — reveal how every category of open-source supply chain risk has materialized in production. The Codecov breach alone generated seven separate company disclosures. The 2025 chalk/debug compromise affected packages with 2 billion weekly downloads. License changes at Elastic, Redis, and HashiCorp forced hundreds of companies into costly migrations. These are not theoretical risks — they are documented engineering crises, mapped below to specific risk check codes.
Active malware and package hijacking dominate the critical category
The critical risk category has the deepest bench of real incidents, spanning account takeovers, dependency confusion, typosquatting, and manifest manipulation.
1. event-stream / flatmap-stream (November 2018)
- Categories: critical, security-vulnerability, continuity-assurance
- Check codes:
PACKAGE_ACTIVE_MALWARE,PACKAGE_INSTALL_SCRIPTS,PACKAGE_PAST_MALWARE,SOURCE_SINGLE_CONTRIBUTOR - What happened: Attacker “right9ctrl” social-engineered maintainer Dominic Tarr into handing over publishing rights to the event-stream npm package (~2M weekly downloads). A malicious dependency (
flatmap-stream) was injected, targeting BitPay’s Copay Bitcoin wallet to steal private keys from accounts holding >100 BTC. - First-person sources:
- Dominic Tarr (original maintainer) — GitHub Gist statement: “He emailed me and said he wanted to maintain the module, so I gave it to him. I don’t get anything from maintaining this module, and I don’t even use it anymore.” (https://gist.github.com/dominictarr/9fd9c1024c94592bc7268d36b8d83b3a)
- BitPay — Official advisory confirming malicious code in Copay versions 5.0.2–5.1.0, advising users to move funds immediately (https://www.bitpay.com/blog/copay-npm-security-update)
- Jayden Seric (developer who first detected it) — Personal blog describing how he traced a crypto deprecation warning in nodemon back to the compromise, reported it to npm, and npm failed to respond for a week (https://jaydenseric.com/blog/event-stream-compromise)
- Aha! Engineering (Zach Schneider) — Technical analysis from an engineering team perspective (https://www.aha.io/engineering/articles/event-stream-vulnerability-explained)
- npm Inc. — Official postmortem with full timeline (https://blog.npmjs.org/post/180565383195/details-about-the-event-stream-incident)
2. ua-parser-js hijack (October 2021)
- Categories: critical, security-vulnerability
- Check codes:
PACKAGE_ACTIVE_MALWARE,PACKAGE_INSTALL_SCRIPTS,PACKAGE_PAST_MALWARE - What happened: The npm account of maintainer Faisal Salman was hijacked. Malicious versions installed a cryptominer and credential stealer targeting FTP passwords, affecting a package with 7M+ weekly downloads.
- First-person sources:
- Faisal Salman (maintainer) — GitHub issue #536: “I noticed something unusual when my email was suddenly flooded by spams from hundreds of websites” (https://github.com/faisalman/ua-parser-js/issues/536)
- JetBrains Kotlin team — Blog post explaining Kotlin/JS users were affected through transitive Karma dependency (https://blog.jetbrains.com/kotlin/2021/10/important-ua-parser-js-exploit-and-kotlin-js/)
- Progress Software (Telerik) — Advisory noting the malware targeted their WS_FTP Professional password files (https://www.progress.com/blogs/malware-found-in-ua-parser-js-npm-library)
- Truesec — Practitioner incident-response blog with remediation steps (https://www.truesec.com/hub/blog/uaparser-js-npm-package-supply-chain-attack-impact-and-response)
3. Codecov bash uploader compromise (April 2021)
- Categories: critical, security-vulnerability
- Check codes:
ARTIFACT_HASH_MISMATCH,PACKAGE_ACTIVE_MALWARE - What happened: Attackers modified Codecov’s bash uploader script to exfiltrate CI/CD environment variables and secrets. A customer performing SHA checksum verification discovered the discrepancy. At least seven companies publicly disclosed being affected.
- First-person sources:
- Codecov — Full postmortem: “Curl pipe to bash, while incredibly convenient, is rife with security issues” (https://about.codecov.io/apr-2021-post-mortem/)
- HashiCorp — First company to publicly disclose; their GPG signing key for Terraform downloads was exposed and rotated (https://discuss.hashicorp.com/t/hcsec-2021-12-codecov-security-event-and-hashicorp-gpg-key-exposure/23512)
- Rapid7 — Confirmed source code repos for internal MDR tooling were accessed, credentials rotated (https://www.rapid7.com/blog/post/2021/05/13/rapid7s-response-to-codecov-incident/)
- Twilio — GitHub notified them of suspicious repo cloning; customer email addresses exfiltrated (https://www.twilio.com/en-us/blog/company/communications/response-to-the-codecov-vulnerability)
- Mercari (Japanese e-commerce) — Most detailed disclosure: 17,085 customer financial records (bank codes, account numbers), 7,966 business partner records, and 2,615 employee records exposed (https://about.mercari.com/en/press/news/articles/20210521_incident_report/)
- Confluent — Attackers gained read-only access to private GitHub repos (https://www.confluent.io/blog/confluent-update-regarding-codecov-incident/)
- Monday.com — Disclosed in SEC F-1 filing that source code was accessed, later discontinued Codecov entirely
- Coalition Inc. — GitHub repos cloned before Codecov’s public disclosure (https://www.coalitioninc.com/blog/security-labs/incident-report-in-response-to-the)
4. eslint-scope account compromise (July 2018)
- Categories: critical, security-vulnerability
- Check codes:
PACKAGE_ACTIVE_MALWARE,PACKAGE_INSTALL_SCRIPTS,PACKAGE_PAST_MALWARE - What happened: An ESLint maintainer’s npm account was compromised (password reuse, no 2FA). Malicious postinstall scripts in eslint-scope stole .npmrc tokens from installers. ~4,500 tokens were potentially compromised.
- First-person sources:
- ESLint team — Detailed postmortem with minute-by-minute timeline (https://eslint.org/blog/2018/07/postmortem-for-malicious-package-publishes/)
- Microsoft Azure DevOps — Proactively revoked at-risk user tokens across their service (https://devblogs.microsoft.com/devops/protecting-our-users-from-the-npm-eslint-package-breach/)
- NodeSource — First-person observer account from someone monitoring the incident in real-time (https://nodesource.com/blog/a-high-level-post-mortem-of-the-eslint-scope-security-incident)
5. Dependency confusion — Alex Birsan’s research (February 2021)
- Categories: critical
- Check codes:
PACKAGE_NAME_MISMATCH,PACKAGE_REGISTRY_MISMATCH - What happened: Researcher Alex Birsan discovered private package names leaked in public repositories and uploaded identically-named packages with higher version numbers to npm/PyPI/RubyGems. He achieved remote code execution on internal servers at 35+ companies including Apple, Microsoft, PayPal, Shopify, Netflix, Tesla, and Uber. Total bug bounties: $130,000+.
- First-person source:
- Alex Birsan — Original Medium write-up detailing the entire methodology (https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610)
- Microsoft — Published whitepaper “3 Ways to Mitigate Risk When Using Private Package Feeds” and issued CVE-2021-24105 for Azure Artifacts
6. PyTorch torchtriton dependency confusion (December 2022)
- Categories: critical, security-vulnerability
- Check codes:
PACKAGE_NAME_MISMATCH,PACKAGE_REGISTRY_MISMATCH,PACKAGE_INSTALL_SCRIPTS - What happened: Attacker registered
torchtritonon PyPI matching PyTorch’s internal package name. Since PyPI takes precedence over private indices, the malicious package was installed instead, exfiltrating SSH keys, .gitconfig, environment variables, and the first 1,000 files in $HOME. Downloaded 2,717+ times over the Christmas holiday. - First-person source:
- PyTorch team — Official blog post: “Since the PyPI index takes precedence, this malicious package was being installed instead of the version from our official repository” (https://pytorch.org/blog/compromised-nightly-dependency/)
7. crossenv typosquatting (August 2017)
- Categories: critical
- Check codes:
PACKAGE_NAME_MISMATCH - What happened: User “hacktask” published ~40 npm packages with names mimicking popular packages (crossenv for cross-env, babelcli for babel-cli, mongose for mongoose). The packages exfiltrated environment variables. ~50 real installations before discovery.
- First-person source:
- npm (CJ Silverio, CTO) — “This time, the package naming was both deliberate and malicious — the intent was to collect useful data from tricked users” (https://blog.npmjs.org/post/163723642530/crossenv-malware-on-the-npm-registry)
8. npm manifest confusion (June 2023)
- Categories: critical, title-assurance
- Check codes:
PACKAGE_REGISTRY_MISMATCH,SOURCE_MALFORMED_METADATA,PACKAGE_SOURCE_URL_MISMATCH - What happened: Darcy Clarke, former Staff Engineering Manager for the npm CLI team at GitHub, discovered that npm’s published manifest does not need to match the package.json inside the actual tarball — enabling hidden dependencies, hidden install scripts, and cache poisoning. GitHub was aware since November 2022 but hadn’t fixed it.
- First-person source:
- Darcy Clarke — Published discovery with proof-of-concept package (
darcyclarke-manifest-pkg) showing zero listed dependencies but actual dependencies in the tarball - JFrog — Follow-up identifying 800+ packages with manifest discrepancies, 18 intentionally exploiting the bug (https://jfrog.com/blog/npm-manifest-confusion-six-months-later/)
- Darcy Clarke — Published discovery with proof-of-concept package (
9. xz utils backdoor (March 2024)
- Categories: critical, security-vulnerability, continuity-assurance
- Check codes:
PACKAGE_ACTIVE_MALWARE,SOURCE_SINGLE_CONTRIBUTOR,SOURCE_FEW_CONTRIBUTORS - What happened: A multi-year social engineering campaign by “Jia Tan” targeted the sole xz utils maintainer, gaining commit access and inserting a sophisticated backdoor into the SSH authentication path. Caught by accident when Microsoft developer Andres Freund noticed a 500ms SSH performance regression.
- First-person sources:
- Andres Freund (discoverer) — Original oss-security mailing list disclosure: “I observed odd behavior in liblzma running on Debian in recent weeks, such as slow logins via SSH and surprisingly high CPU usage” (https://www.openwall.com/lists/oss-security/2024/03/29/4)
- Red Hat — Detailed incident response blog describing cross-team mobilization including developers, pen-testers, offensive analysts, and engagement with CISA (https://www.redhat.com/en/blog/understanding-red-hats-response-xz-security-incident)
- Lasse Collin (original xz maintainer) — Statement on the backdoor (https://tukaani.org/xz-backdoor/)
- Canonical/Ubuntu — Postponed Ubuntu 24.04 LTS beta by one week and conducted full binary rebuild
10. Ledger Connect Kit hack (December 2023)
- Categories: critical, security-vulnerability
- Check codes:
PACKAGE_ACTIVE_MALWARE,ARTIFACT_HASH_MISMATCH - What happened: An ex-employee’s account was phished, giving attackers access to Ledger’s NPMJS publishing account. Malicious versions of the Connect Kit (1.1.5–1.1.7) injected Angel Drainer malware into every dApp using the library. $600K+ stolen from users within hours.
- First-person sources:
- Ledger — CEO letter and security incident report with full timeline (https://www.ledger.com/blog/security-incident-report)
- Revoke.cash (Rosco Kalis) — Gold-standard downstream victim account: “I was having lunch with my friend David when I noticed notifications… I left David with the lunch bill and sprinted back to the office.” Paid Vercel $150 to lock their site. Couldn’t pin the library because Ledger distributed via CDN, not pinnable npm versions. (https://revoke.cash/blog/2023/ledger-connect-kit-hack-retrospective)
- Blockaid — Detected attack within 6 minutes (https://www.blockaid.io/blog/attack-report-ledger-connect-kit)
11. Lottie Player supply chain attack (October 2024)
- Categories: critical, security-vulnerability
- Check codes:
PACKAGE_ACTIVE_MALWARE,ARTIFACT_HASH_MISMATCH - What happened: A compromised developer access token was used to publish malicious versions (2.0.5–2.0.7) of the popular @lottiefiles/lottie-player npm package. The payload (Ace Drainer) targeted crypto wallets. One user reportedly lost 10 BTC ($723K). Blockaid identified 400+ affected websites including Toshiba, Dream11, and Ingenico.
- First-person sources:
- LottieFiles — Confirmed on X that unauthorized versions were uploaded via compromised token
- 1inch (DeFi platform) — Confirmed users between Oct 30 9:12–11:22 PM CET may have been shown malicious wallet connect prompts
- Blockaid — Attack report detailing detection and $750K saved (https://www.blockaid.io/blog/attack-report-lottie-player-supply-chain-attack)
12. Polyfill.io domain takeover (June 2024)
- Categories: critical, title-assurance
- Check codes:
PACKAGE_UNSAFE_SOURCE_URL,PACKAGE_SOURCE_URL_MISMATCH - What happened: The polyfill.io domain was acquired by a Chinese entity (Funnull) that injected malicious redirects into the JavaScript served to 100,000+ websites, including JSTOR, Intuit, World Economic Forum, Hulu, and Mercedes-Benz.
- First-person sources:
- Andrew Betts (original polyfill.io creator) — Warning on X: “I created the polyfill service project but I have never owned the domain and I have had no influence over its sale”
- Cloudflare — Took “exceptional step” of rewriting HTML on the fly to replace polyfill.io references across all free-plan customer sites (https://blog.cloudflare.com/automatically-replacing-polyfill-io-links-with-cloudflares-mirror-for-a-safer-internet)
- Sansec — Original discoverers of the malicious code injection (https://sansec.io/research/polyfill-supply-chain-attack)
13. Shai-Hulud npm worm / chalk-debug compromise (September 2025)
- Categories: critical, security-vulnerability, continuity-assurance
- Check codes:
PACKAGE_ACTIVE_MALWARE,PACKAGE_INSTALL_SCRIPTS,SOURCE_SINGLE_CONTRIBUTOR - What happened: A phishing email from npmjs[.]help compromised maintainer Josh Junon’s account. Self-replicating postinstall scripts harvested npm tokens, GitHub PATs, and cloud credentials, then automatically published malicious versions of every package the compromised account controlled. 500+ packages compromised including chalk and debug (2 billion weekly downloads combined). CISA issued a formal alert.
- First-person sources:
- Josh Junon “Qix-” (compromised maintainer) — “Sorry everyone, I should have paid more attention. Not like me; have had a stressful week.”
- JFrog — “The most widespread supply chain attack in npm’s history” (https://jfrog.com/blog/new-compromised-packages-in-largest-npm-attack-in-history/)
- StepSecurity — Documented the worm’s postinstall mechanism across 40+ packages (https://www.stepsecurity.io/blog/ctrl-tinycolor-and-40-npm-packages-compromised)
- CISA — Formal alert about the self-replicating worm (https://www.cisa.gov/news-events/alerts/2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem)
14. coa and rc npm packages (November 2021)
- Categories: critical, security-vulnerability
- Check codes:
PACKAGE_ACTIVE_MALWARE,PACKAGE_INSTALL_SCRIPTS,PACKAGE_PAST_MALWARE - What happened: Popular npm packages coa and rc were hijacked via compromised maintainer accounts. Malicious preinstall scripts ran password-stealing malware. React build pipelines globally were disrupted because coa is deep in the React toolchain.
- First-person source:
- Developer community — GitHub issues: “10 minutes ago there was a release (even though the last change on GitHub was in 2018). Whatever this release did, it broke the internet.”
15. tj-actions/changed-files GitHub Action compromise (March 2025)
- Categories: critical, security-vulnerability
- Check codes:
PACKAGE_ACTIVE_MALWARE,PACKAGE_INSTALL_SCRIPTS - What happened: Attackers compromised a SpotBugs maintainer PAT, pivoted through reviewdog/action-setup to tj-actions/changed-files, and injected secret-dumping code into a GitHub Action used by 23,000 repositories. 218 repos confirmed to have leaked secrets. Coinbase was the initial target.
- First-person sources:
- StepSecurity — Harden-Runner detected the unauthorized outbound call (https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised)
- Coinbase — Confirmed as initial target; attacker obtained a write-permission GitHub token but failed to access secrets (per Unit 42 report)
- Wiz Research — Reconstructed the full attack chain (https://www.wiz.io/blog/github-action-tj-actions-changed-files-supply-chain-attack-cve-2025-30066)
Maintainer burnout and bus factor risk have broken production at scale
The continuity-assurance category tracks single-contributor dependencies, abandoned repositories, and stale packages. These incidents prove these risks are not hypothetical.
16. left-pad removal (March 2016)
- Categories: continuity-assurance, security-vulnerability
- Check codes:
SOURCE_SINGLE_CONTRIBUTOR,PACKAGE_STALE_RELEASE - What happened: After a trademark dispute with Kik, developer Azer Koçulu unpublished all 273 of his npm packages, including left-pad (11 lines of code). Babel, React, and thousands of dependent packages immediately broke. npm took the unprecedented step of restoring the package from backup.
- First-person sources:
- npm (Laurie Voss, CTO) — “Un-un-publishing is an unprecedented action… This action puts the wider interests of the community at odds with the wishes of one author; we picked the needs of the many.” (https://blog.npmjs.org/post/141577284765/kik-left-pad-and-npm)
- Pusher — Engineering team blog reflecting on dependency risk (https://pusher.com/blog/talking-left-pad-npm-and-dependencies-in-front-end-development/)
17. core-js single-maintainer crisis (2019–present)
- Categories: continuity-assurance, security-vulnerability
- Check codes:
SOURCE_SINGLE_CONTRIBUTOR,SOURCE_FEW_CONTRIBUTORS - What happened: core-js — used on 50%+ of the world’s top websites, 25M weekly downloads — is maintained by a single developer, Denis Pushkarev, who went to prison, faced $80K in claims, and earned $57/month from the project. Amazon, Netflix, Apple, LinkedIn, and PayPal all depend on it.
- First-person source:
- Denis Pushkarev — 11,000-word GitHub manifesto: “When I started raising funds to support core-js development… The result was… $57/month.” (https://github.com/zloirock/core-js/blob/master/docs/2023-02-14-so-whats-next.md)
- John McBride — Analysis from affected developer perspective: “A solo maintainer project that Amazon, Netflix, Apple, LinkedIn, PayPal, Binance, and tens of thousands of others have a dependency on… is a prime target for state-sponsored hacker groups.” (https://johncodes.com/archive/2023/04-22-revisiting-the-core-js-situation/)
18. colors.js / faker.js sabotage (January 2022)
- Categories: continuity-assurance, security-vulnerability, critical
- Check codes:
SOURCE_SINGLE_CONTRIBUTOR,PACKAGE_PAST_MALWARE,PACKAGE_ACTIVE_MALWARE - What happened: Maintainer Marak Squires deliberately introduced an infinite loop printing “LIBERTY” in colors.js (23M weekly downloads) and deleted faker.js (2.4M weekly downloads) to protest unpaid maintenance of Fortune 500 dependencies. Amazon AWS CDK, Facebook’s Jest, and thousands of projects broke immediately.
- First-person sources:
- Marak Squires — November 2020 warning: “I am no longer going to support Fortune 500s with my free work”
- AWS CDK users — GitHub issues documenting applications producing only gibberish “LIBERTY LIBERTY LIBERTY” output
- FOSSA — Engineering perspective on the 23M-download impact (https://fossa.com/blog/npm-packages-colors-faker-corrupted/)
19. node-ipc protestware / peacenotwar (March 2022)
- Categories: critical, security-vulnerability, continuity-assurance
- Check codes:
PACKAGE_ACTIVE_MALWARE,PACKAGE_PAST_MALWARE,SOURCE_SINGLE_CONTRIBUTOR - What happened: Developer Brandon Nozaki Miller added code to node-ipc (1M+ weekly downloads) that overwrote all files with heart emojis on systems geolocated in Russia or Belarus. Later versions dropped “peacenotwar” files. Affected Vue.js CLI users globally.
- First-person sources:
- Anonymous American NGO — GitHub post (since removed): “One of the web services used to contact us securely was hosted on servers inside Belarus… package containing node-ipc was updated on a production server, which resulted in executing your code and wiping over 30,000 messages and files.”
- Unity Technologies — Issued hotfix for Unity Hub 3.1 which pulled in the peacenotwar file-dropping version
- Styled-components maintainer Evan Jacobs — First-person interview on related protestware: “We had a unique opportunity to deliver a concise message via an atypical channel: our npm package installations” (TechCrunch)
20. Heartbleed / OpenSSL underfunding (April 2014)
- Categories: continuity-assurance, security-vulnerability
- Check codes:
SOURCE_FEW_CONTRIBUTORS,VULN_HISTORICAL_SEVERE,VULN_UNFIXED - What happened: A critical vulnerability in OpenSSL — maintained by essentially one full-time person — allowed attackers to extract private keys from server memory. Cloudflare revoked and reissued over 100,000 TLS certificates. Mandiant documented active exploitation bypassing multi-factor authentication within days.
- First-person sources:
- Cloudflare — “We revoked and reissued every single certificate we manage” — over 100,000 certificates, causing GlobalSign’s CRL to grow from 22KB to 4.7MB in one day (https://blog.cloudflare.com/the-heartbleed-aftermath-all-cloudflare-certificates-revoked-and-reissued/)
- Mandiant/Google Cloud — Documented attackers exploiting Heartbleed against a client’s VPN appliance: “IDS signature alerted over 17,000 times during the intrusion” (https://cloud.google.com/blog/topics/threat-intelligence/attackers-exploit-heartbleed-openssl-vulnerability/)
- Private Internet Access — “All of our VPN gateways were patched within 4 hours of the public disclosure” (https://privateinternetaccess.com/blog/2014/04/heartbleed-post-mortem)
21. Log4Shell / Log4j (December 2021)
- Categories: security-vulnerability, continuity-assurance
- Check codes:
VULN_HISTORICAL_SEVERE,VULN_RECENT_FREQUENCY,SOURCE_FEW_CONTRIBUTORS - What happened: A critical RCE vulnerability in Apache Log4j affected virtually every Java application. Arctic Wolf reported one in four organizations in their customer base were targeted, with average incident response costs exceeding $90,000.
- First-person sources:
- Adrianna Gugel (CPO at Flux) — Deeply personal account: “December 9, 2021 will forever be etched in the memories of software engineering leaders… our SVP of Engineering was woken on a Friday evening in Europe, the CEO demanding immediate answers, engineering teams working around the clock.” (https://www.askflux.ai/blog/log4shell-software-vulnerability-incident-response)
- Cloudflare — Found vulnerable Log4j in their ElasticSearch, LogStash, and Bitbucket systems (https://blog.cloudflare.com/how-cloudflare-security-responded-to-log4j2-vulnerability/)
- Rapid7 — “Log4Shell has kept the security community extremely busy… we are no exception.” Discovered their own Metasploit Pro shipped with Log4j. (https://www.rapid7.com/blog/post/2021/12/14/update-on-log4shells-impact-on-rapid7-solutions-and-systems/)
22. Dependency rot — developer rewrite story
- Categories: continuity-assurance, security-vulnerability
- Check codes:
PACKAGE_STALE_RELEASE,LAST_COMMIT_OVER_A_YEAR,PACKAGE_SKEW_NOT_UPDATED - What happened: Developer Matt March documented 106 accumulated dependency issues in a Gatsby blog after “laziness took over” on Dependabot PRs. Ultimately rewrote the entire application rather than fix the dependency rot.
- First-person source:
- Matt March — “Dependency rot had set in… I’d built the entire blog in a weekend, did I really want to spend another weekend fixing dependencies? Wouldn’t it be faster to just rewrite it from scratch?” (https://mattmarch.com/posts/dependency-rot)
License compliance failures have cost companies millions in litigation and rewrites
The license-compliance and title-assurance categories cover some of the most expensive incidents, including a €900,000 judgment and a proposed $100M lawsuit.
23. Entr’ouvert v. Orange — €900K GPL violation (2011–2024)
- Categories: license-compliance
- Check codes:
LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT,LICENSE_NOT_APPROVED - What happened: Orange S.A. (French telecom giant) modified and distributed Entr’ouvert’s GPL v2-licensed “Lasso” authentication library in a public portal without complying with source code disclosure requirements. Paris Court of Appeal ordered Orange to pay over €900,000 (~$1M) — the largest GPL-related fine on record.
- First-person source:
- FossID/FOSSA — Detailed case analysis (https://fossid.com/articles/open-source-license-compliance-lessons-from-two-landmark-court-cases/)
24. Versata / XimpleWare — GPL violation discovered during litigation (2013–2015)
- Categories: license-compliance, title-assurance
- Check codes:
LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT,LICENSE_REFERENCE_MISSING_FILE,PACKAGE_NO_LICENSE - What happened: Versata incorporated XimpleWare’s GPL-licensed VTD-XML parser into proprietary software, stripped the GPL license text and copyright notices, and distributed it commercially. The violation was discovered accidentally during unrelated litigation when customer Ameriprise examined Versata’s code. Spawned five separate court proceedings. XimpleWare sought $300M in damages.
- First-person source:
- CIO magazine — “Versata did not appear to have a process for managing open source software. They ignored it.” (https://www.cio.com/article/246401/how-2-legal-cases-may-decide-the-future-of-open-source-software.html)
25. Tendermint/Cosmos — GPL contamination in Apache 2.0 project (2018)
- Categories: license-compliance
- Check codes:
LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT,LICENSE_NOT_APPROVED - What happened: A community member discovered Tendermint’s Merkle tree code (Apache 2.0 licensed) was derived from a GPL v2-licensed library. This potentially GPL-contaminated the entire Tendermint/Cosmos blockchain codebase.
- First-person source:
- johndpope — GitHub issue #1111: “Unfortunately - all derivative works become GPL” (https://github.com/tendermint/tendermint/issues/1111)
26. BusyBox GPL enforcement — 14+ companies sued (2007–2013)
- Categories: license-compliance
- Check codes:
LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT,LICENSE_REFERENCE_MISSING_FILE - What happened: SFLC and FSF filed lawsuits against Monsoon Multimedia, Xterasys, Verizon, Best Buy, Samsung, Westinghouse, and others for distributing BusyBox code in consumer products without GPL v2 source disclosure. Westinghouse ordered to pay over $100,000. FSF v. Cisco resulted in Cisco appointing a dedicated Free Software Compliance Officer.
- Source: https://fossa.com/blog/analyzing-5-major-oss-license-compliance-lawsuits/
27. CoKinetic v. Panasonic Avionics — $100M+ GPL lawsuit
- Categories: license-compliance
- Check codes:
LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT - What happened: CoKinetic sued Panasonic Avionics for over $100 million, alleging Panasonic’s Linux-based in-flight entertainment OS violated GPL v2 by refusing to distribute source code, using license noncompliance as a competitive moat.
- Source: https://www.mend.io/blog/the-100-million-case-for-open-source-license-compliance/
28. SFC v. Vizio — third-party GPL enforcement precedent (2021–present)
- Categories: license-compliance
- Check codes:
LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT - What happened: Software Freedom Conservancy sued Vizio for failing to release SmartCast OS source code. The ruling established that any third party worldwide is a legitimate beneficiary of a GPL license and can bring suit — not just the copyright holder.
- Source: https://meitar.com/en/media/contamination-alert-third-parties-can-now-enforce-the-terms-of-the-gpl-license/
29. Sebastian Steck v. AVM — individual enforces LGPL (2021–2024)
- Categories: license-compliance
- Check codes:
LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT,LICENSE_REFERENCE_MISSING_FILE - What happened: Individual developer purchased an AVM router, requested LGPL-required source code, was refused, and won a court judgment of €7,500 plus full source disclosure. A “David vs. Goliath” enforcement case.
- Source: https://fossid.com/articles/open-source-license-compliance-lessons-from-two-landmark-court-cases/
30. Patrick McHardy — GPL copyright troll targeting ~80 companies (2012–2019)
- Categories: license-compliance
- Check codes:
LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT,LICENSE_MODIFIED - What happened: Linux kernel contributor Patrick McHardy used German courts to extract monetary settlements from approximately 80 companies for minor GPL attribution deficiencies, with contractual penalties up to €250,000 per violation. Many settlements included NDAs.
- Source: https://www.blackduck.com/blog/top-10-open-source-legal-issues-2019.html
31. SaaS company forced $300K AGPL rewrite
- Categories: license-compliance
- Check codes:
LICENSE_RESTRICTION_NETWORK_COPYLEFT - What happened: A mid-sized SaaS company discovered their legal team had failed to catch an AGPL-licensed library in their stack. They were forced to rewrite six months of work at a cost of $300,000 and a three-month product launch delay.
- First-person source:
- Sohail Saifi — Medium post calling AGPL “the most dangerous license in open source” for commercial SaaS companies (https://medium.com/@sohail_saifi/the-open-source-license-thats-quietly-bankrupting-companies-1ab583f853be)
32. Google’s AGPL ban — company-wide policy
- Categories: license-compliance
- Check codes:
LICENSE_RESTRICTION_NETWORK_COPYLEFT,LICENSE_NOT_APPROVED - What happened: Google maintains a strict company-wide policy prohibiting any use of AGPL-licensed code, treating it as an absolute non-starter for internal systems. This is the most prominent example of a major tech company’s license risk mitigation.
- Source: https://fossa.com/blog/open-source-software-licenses-101-agpl-license/
License changes forced hundreds of companies into costly migrations
33. Elastic license change — Logz.io forced to migrate entire backend (2021)
- Categories: license-compliance, title-assurance
- Check codes:
LICENSE_RESTRICTION_COMMERCIAL,LICENSE_NOT_APPROVED,PACKAGE_LICENSE_MISMATCH - What happened: When Elastic changed from Apache 2.0 to SSPL/Elastic License, Logz.io — built entirely on Elasticsearch since founding — had to migrate its entire backend to OpenSearch, replace Kibana with OpenSearch Dashboards, and swap Filebeat for Fluentd. At SRECon24, their developer advocate described these as “insightful — and at times painful — experiences.”
- First-person sources:
- Logz.io CEO Tomer Levy — “This license change is not OK… it betrays the community” (https://logz.io/blog/open-source-elasticsearch-doubling-down/)
- Elastic CEO Shay Banon — Counter-perspective: “This was an incredibly hard decision… AWS has been doing things that we think are just NOT OK since 2015” (https://www.elastic.co/blog/why-license-change-aws)
34. Bonsai — world’s first Elasticsearch host navigates license change (2021)
- Categories: license-compliance
- Check codes:
LICENSE_RESTRICTION_COMMERCIAL,PACKAGE_LICENSE_MISMATCH - What happened: Small, bootstrapped hosting company Bonsai discovered the new SSPL would require them to release their entire management stack as open source. They published an open letter to customers and ultimately added OpenSearch support.
- First-person source:
- Bonsai — “Our best and only understanding of our responsibilities at the time was the project’s Apache 2.0 license… We dove into the deep-end of scaling and supporting Elasticsearch.” (https://bonsai.io/blog/open-letter-to-bonsai-customers/)
35. HashiCorp BSL change — OpenTofu manifesto signed by 140+ companies (2023)
- Categories: license-compliance
- Check codes:
LICENSE_RESTRICTION_COMMERCIAL,LICENSE_NOT_APPROVED - What happened: HashiCorp’s switch from MPL 2.0 to BSL prompted 140+ companies and 700+ individuals to sign the OpenTF manifesto: “Overnight, tens of thousands of businesses woke up to a new reality where the underpinnings of their infrastructure suddenly became a potential legal risk.” The community forked Terraform as OpenTofu.
- First-person source:
- Spacelift — Direct challenge to HashiCorp’s “freeloading” narrative (https://spacelift.io/blog/terraform-license-change)
- OpenTF Manifesto — 33,000+ GitHub stars
36. Redis license change — CEO admits it backfired (2024–2025)
- Categories: license-compliance
- Check codes:
LICENSE_RESTRICTION_COMMERCIAL,LICENSE_NOT_APPROVED - What happened: Redis changed from BSD to RSALv2/SSPLv1. CEO Rowan Trollope later admitted: “No matter how much I said that the SSPL is essentially the same as open source, it was like pushing string uphill. And I was: ‘This isn’t working. Like, oh shit, what do we do now?’” Triggered the creation of Valkey (Amazon-backed fork). Redis ultimately returned to open source with Redis 8.
- First-person sources:
- Redis CEO — (https://thenewstack.io/redis-is-open-source-again/)
- authentik Security — Removed Redis from their stack due to license trust erosion: “Even after Redis back-pedaled… the fragmentation and loss of trust caused by the initial change caused cloud providers to continue to use Valkey.” (https://goauthentik.io/blog/2025-11-13-we-removed-redis/)
37. Black Duck OSSRA — 53% of M&A audits found license conflicts
- Categories: license-compliance, title-assurance
- Check codes:
PACKAGE_LICENSE_MISMATCH,PACKAGE_NO_LICENSE,LICENSE_NOT_APPROVED - What happened: Over 53% of codebases audited during M&A due diligence in 2023 contained open source with license conflicts. Compliance issues have delayed deals and altered acquisition terms.
- Source: https://www.blackduck.com/blog/ossra-license-compliance-risks.html
Lockfile and install-script vectors round out the attack surface
38. Lockfile injection — demonstrated attack vector (2019)
- Categories: security-vulnerability
- Check codes: Missing Lockfiles,
PACKAGE_INSTALL_SCRIPTS - What happened: Liran Tal at Snyk demonstrated that attackers could modify package-lock.json to specify malicious package sources in the
resolvedfield and update integrity hashes to match — injecting backdoors through pull requests that modify lockfiles. Created thelockfile-linttool as a countermeasure. - First-person source:
Comprehensive incident-to-category mapping
| # | Incident | Year | Categories | Key Check Codes |
|---|---|---|---|---|
| 1 | event-stream | 2018 | critical, security-vulnerability, continuity-assurance | PACKAGE_ACTIVE_MALWARE, PACKAGE_INSTALL_SCRIPTS, SOURCE_SINGLE_CONTRIBUTOR |
| 2 | ua-parser-js | 2021 | critical, security-vulnerability | PACKAGE_ACTIVE_MALWARE, PACKAGE_INSTALL_SCRIPTS |
| 3 | Codecov bash uploader | 2021 | critical, security-vulnerability | ARTIFACT_HASH_MISMATCH, PACKAGE_ACTIVE_MALWARE |
| 4 | eslint-scope | 2018 | critical, security-vulnerability | PACKAGE_ACTIVE_MALWARE, PACKAGE_INSTALL_SCRIPTS |
| 5 | Dependency confusion (Birsan) | 2021 | critical | PACKAGE_NAME_MISMATCH, PACKAGE_REGISTRY_MISMATCH |
| 6 | PyTorch torchtriton | 2022 | critical, security-vulnerability | PACKAGE_NAME_MISMATCH, PACKAGE_REGISTRY_MISMATCH, PACKAGE_INSTALL_SCRIPTS |
| 7 | crossenv typosquatting | 2017 | critical | PACKAGE_NAME_MISMATCH |
| 8 | npm manifest confusion | 2023 | critical, title-assurance | PACKAGE_REGISTRY_MISMATCH, SOURCE_MALFORMED_METADATA, PACKAGE_SOURCE_URL_MISMATCH |
| 9 | xz utils backdoor | 2024 | critical, security-vulnerability, continuity-assurance | PACKAGE_ACTIVE_MALWARE, SOURCE_SINGLE_CONTRIBUTOR, SOURCE_FEW_CONTRIBUTORS |
| 10 | Ledger Connect Kit | 2023 | critical, security-vulnerability | PACKAGE_ACTIVE_MALWARE, ARTIFACT_HASH_MISMATCH |
| 11 | Lottie Player | 2024 | critical, security-vulnerability | PACKAGE_ACTIVE_MALWARE, ARTIFACT_HASH_MISMATCH |
| 12 | Polyfill.io | 2024 | critical, title-assurance | PACKAGE_UNSAFE_SOURCE_URL, PACKAGE_SOURCE_URL_MISMATCH |
| 13 | Shai-Hulud / chalk-debug | 2025 | critical, security-vulnerability, continuity-assurance | PACKAGE_ACTIVE_MALWARE, PACKAGE_INSTALL_SCRIPTS, SOURCE_SINGLE_CONTRIBUTOR |
| 14 | coa/rc packages | 2021 | critical, security-vulnerability | PACKAGE_ACTIVE_MALWARE, PACKAGE_INSTALL_SCRIPTS |
| 15 | tj-actions/changed-files | 2025 | critical, security-vulnerability | PACKAGE_ACTIVE_MALWARE, PACKAGE_INSTALL_SCRIPTS |
| 16 | left-pad | 2016 | continuity-assurance, security-vulnerability | SOURCE_SINGLE_CONTRIBUTOR, PACKAGE_STALE_RELEASE |
| 17 | core-js | 2019–now | continuity-assurance, security-vulnerability | SOURCE_SINGLE_CONTRIBUTOR, SOURCE_FEW_CONTRIBUTORS |
| 18 | colors.js / faker.js | 2022 | continuity-assurance, security-vulnerability, critical | SOURCE_SINGLE_CONTRIBUTOR, PACKAGE_PAST_MALWARE |
| 19 | node-ipc protestware | 2022 | critical, security-vulnerability, continuity-assurance | PACKAGE_ACTIVE_MALWARE, SOURCE_SINGLE_CONTRIBUTOR |
| 20 | Heartbleed / OpenSSL | 2014 | continuity-assurance, security-vulnerability | SOURCE_FEW_CONTRIBUTORS, VULN_HISTORICAL_SEVERE |
| 21 | Log4Shell | 2021 | security-vulnerability, continuity-assurance | VULN_HISTORICAL_SEVERE, VULN_RECENT_FREQUENCY, SOURCE_FEW_CONTRIBUTORS |
| 22 | Dependency rot (Matt March) | 2023 | continuity-assurance, security-vulnerability | PACKAGE_STALE_RELEASE, LAST_COMMIT_OVER_A_YEAR, PACKAGE_SKEW_NOT_UPDATED |
| 23 | Entr’ouvert v. Orange | 2011–2024 | license-compliance | LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT |
| 24 | Versata / XimpleWare | 2013–2015 | license-compliance, title-assurance | LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT, LICENSE_REFERENCE_MISSING_FILE, PACKAGE_NO_LICENSE |
| 25 | Tendermint GPL contamination | 2018 | license-compliance | LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT, LICENSE_NOT_APPROVED |
| 26 | BusyBox GPL enforcement | 2007–2013 | license-compliance | LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT, LICENSE_REFERENCE_MISSING_FILE |
| 27 | CoKinetic v. Panasonic | 2017–2018 | license-compliance | LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT |
| 28 | SFC v. Vizio | 2021–now | license-compliance | LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT |
| 29 | Steck v. AVM | 2021–2024 | license-compliance | LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT, LICENSE_REFERENCE_MISSING_FILE |
| 30 | McHardy GPL troll | 2012–2019 | license-compliance | LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT, LICENSE_MODIFIED |
| 31 | AGPL rewrite ($300K) | ~2025 | license-compliance | LICENSE_RESTRICTION_NETWORK_COPYLEFT |
| 32 | Google AGPL ban | Ongoing | license-compliance | LICENSE_RESTRICTION_NETWORK_COPYLEFT, LICENSE_NOT_APPROVED |
| 33 | Elastic license → Logz.io | 2021 | license-compliance, title-assurance | LICENSE_RESTRICTION_COMMERCIAL, PACKAGE_LICENSE_MISMATCH |
| 34 | Elastic license → Bonsai | 2021 | license-compliance | LICENSE_RESTRICTION_COMMERCIAL, PACKAGE_LICENSE_MISMATCH |
| 35 | HashiCorp BSL → OpenTofu | 2023 | license-compliance | LICENSE_RESTRICTION_COMMERCIAL, LICENSE_NOT_APPROVED |
| 36 | Redis license → Valkey fork | 2024 | license-compliance | LICENSE_RESTRICTION_COMMERCIAL, LICENSE_NOT_APPROVED |
| 37 | Black Duck OSSRA audits | 2024 | license-compliance, title-assurance | PACKAGE_LICENSE_MISMATCH, PACKAGE_NO_LICENSE |
| 38 | Lockfile injection (Snyk) | 2019 | security-vulnerability | Missing Lockfiles, PACKAGE_INSTALL_SCRIPTS |
Conclusion: every risk check code maps to real wreckage
Three patterns stand out across these 38 incidents. First, single-maintainer risk is the root cause of the majority of critical incidents — event-stream, xz utils, colors/faker, core-js, Heartbleed, and the chalk/debug worm all trace back to packages where one person held the keys. The SOURCE_SINGLE_CONTRIBUTOR and SOURCE_FEW_CONTRIBUTORS checks would have flagged every one of these before exploitation.
Second, license compliance failures are slow-motion disasters that surface during M&A, litigation, or competitive pressure. The Versata case was discovered by accident during unrelated litigation. The Entr’ouvert case took 13 years to resolve. Over half of all M&A code audits reveal license conflicts. The LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT and LICENSE_NOT_APPROVED checks address the most financially devastating category of supply chain risk.
Third, install-time script execution is the primary technical vector for turning a compromised package into a compromised system. The event-stream, eslint-scope, ua-parser-js, coa/rc, Shai-Hulud worm, and tj-actions incidents all leveraged postinstall or preinstall scripts to execute malicious code. The PACKAGE_INSTALL_SCRIPTS check flags this attack surface directly — and the npm registry itself acknowledged in 2016 that “the utility of having installation scripts is greater than the risk of worms,” a judgment the subsequent decade has thoroughly tested.