Supply Chain Risk Guard Checks: Real-World Incident Mapping

Every one of these 36 risk checks corresponds to a documented attack or incident across npm, PyPI, Maven, and other ecosystems. From the xz utils backdoor that nearly compromised every Linux server on Earth to the Equifax breach that exposed 147 million Americans, these incidents demonstrate why automated supply chain risk detection matters.


Malware, Impersonation, and Malicious Code

Check: Source repository could not be found or cloned.

Unit42 discovered six malicious PyPI packages in March 2023 published by accounts using a “1337” suffix pattern (e.g., Anne1337, Richard1337). Each account uploaded only a single package. The critical indicator: the packages lacked any associated GitHub repository, which Unit42 explicitly flagged as a malware signal, noting this “could indicate a desire to hide the code from view.” The packages collected sensitive data and exfiltrated it to third-party URLs.

In February 2025, Socket.dev identified event-handle-package on npm as part of a Lazarus Group campaign — published with no publicly linked repository at all. Phylum’s automated detection system has documented “missing link to a version control system” as a top-tier malware indicator since March 2022.

Discovered by: Palo Alto Networks Unit42; Socket.dev; Phylum


2. SOURCE_MALFORMED_METADATA — A stray backtick in Geronimo’s POM broke ActiveMQ builds

Check: Dependency files contain syntax errors or are malformed.

The Apache Geronimo parent POM org.apache.geronimo.specs:specs:pom:1.1, published to Maven Central, contained a stray backtick character after the closing </developers> tag on line 90, making it syntactically invalid XML. The error manifested as: expected START_TAG or END_TAG not TEXT. Any project depending on Apache ActiveMQ (specifically activemq-spring:5.15.0 → activemq-pool → activemq-jms-pool → geronimo-jta_1.0.1B_spec:1.0.1 → parent specs:1.1) experienced build failures when using JFrog Artifactory as a repository mirror. Maven’s lenient XML parser ignored it, but Artifactory’s stricter parser rejected the malformed POM entirely. The issue was reported as blocker-priority in September 2017 but was never fixed because Maven Central artifacts are immutable.

Separately, MNG-6020 documented that a POM with an extra trailing </project> tag (invalid XML) was successfully deployed to Maven Central — Maven’s parser stopped reading after the first closing tag and silently ignored trailing content.

Discovered by: Apache Geronimo community; Maven developers (GERONIMO-6590, MNG-6020)


3. PACKAGE_NO_LICENSE — Unlicensed packages create M&A compliance blockers

Check: Package does not declare a license in registry metadata.

FossID documented the npm package jquery.connectingLine during real client compliance audits in 2025 as having “no license file, no declared license and no mention of licensing in the readme or elsewhere in the repository.” FossID warned: “You cannot comply with a license if you do not know what it is.”

The Synopsys Black Duck 2024 OSSRA report (analyzing 1,067 commercial codebases during M&A due diligence) found 31% of audited codebases contained open source with no discernible license. The 2025 edition saw this rise to 33%. These are real M&A audit findings where missing license declarations created concrete compliance blockers that delayed or derailed acquisitions.

Discovered by: FossID; Synopsys Black Duck


4. PACKAGE_REGISTRY_MISMATCH — Dependency confusion attack (February 2021)

Check: Package does not exist in the package registry, or claims to be private but is published.

Security researcher Alex Birsan published 200+ new packages on npm, PyPI, and RubyGems with names matching companies’ internal/private packages. Package managers preferentially installed the public version when it had a higher version number. The packages contained DNS exfiltration callbacks that reported hostnames and usernames. Apple, Microsoft, PayPal, Shopify, Netflix, Tesla, Uber, and 28+ other organizations were breached. Birsan earned over $130,000 in bug bounties. Microsoft assigned CVE-2021-24105, and Orca Security later found ~49% of organizations remain vulnerable.

Discovered by: Alex Birsan


5. PACKAGE_UNSAFE_SOURCE_URL — Abandoned python-distribute.org domain

Check: Package metadata contains invalid or unsafe source URLs.

ReversingLabs discovered in November 2025 that popular PyPI packages including tornado, pypiserver, and slapos.core shipped legacy bootstrap.py scripts with hardcoded references to python-distribute.org — a domain abandoned since 2014, currently parked and for sale. If purchased by a threat actor, it could serve malicious payloads executed automatically via exec() with no integrity checks. A precedent exists: in 2023, an attacker registered a lapsed domain hardcoded in npm’s fsevents package (CVE-2023-45311), successfully executing this exact attack pattern.

Discovered by: ReversingLabs


6. PACKAGE_SOURCE_URL_MISMATCH — StarJacking attacks faked repository URLs on PyPI

Check: Package registry reports different source repository than analyzed repository.

In June 2022, Checkmarx documented a technique they named “StarJacking.” The malicious PyPI package pampyio set its repository URL to point to the legitimate pampy project’s GitHub repository. PyPI displayed the real pampy project’s stars and statistics on pampyio’s page. The package accumulated 70,000+ downloads. Its actual code included a malicious dependency redapty that exfiltrated environment variables.

A second wave in August 2022 saw packages typing-unions and aiogram-types point their repo URLs to the legitimate typing project (9M+ monthly downloads) and aiogram respectively. The packages’ actual code bore no resemblance to the linked repos and delivered Cobalt Strike beacons.

Discovered by: Checkmarx Supply Chain Security


7. PACKAGE_LICENSE_MISMATCH — @pkgjs/parseargs declared MIT but LICENSE file said Apache 2.0

Check: Package registry license differs from source repository license(s).

FossID documented in 2025 that the npm package @pkgjs/parseargs showed MIT license in its package.json (displayed on npm registry), while the actual LICENSE file in the repository contained Apache License 2.0. Issues were raised on GitHub asking contributors if they were happy to release under MIT. The change was made in main but never published as a tagged release, so the mismatch persists on npm.

This left users unable to determine which license actually applied. The broader Synopsys 2024 OSSRA report found 53% of audited codebases contained license conflicts during M&A due diligence — many attributable to registry-vs-source mismatches like this.

Discovered by: FossID; multiple compliance audit teams


8. PACKAGE_NAME_MISMATCH — crytic-compilers published under a different name than its source

Check: Published package has different name than source repository.

Socket Research Team documented that “while the package is named ‘crytic-compilers’ on the PyPI registry, it’s listed as ‘crytic-compile’ on the corresponding GitHub page.” The legitimate package is crytic-compile, a smart contract compilation utility maintained by Trail of Bits (~6,000 downloads/day). The malicious crytic-compilers contained a Windows trojan (s.exe). To maintain plausibility, the attacker’s setup.py also downloaded the legitimate crytic-compile source from GitHub. The package accumulated 388 downloads before removal.

In March 2023, ReversingLabs documented termcolour on PyPI with the same pattern: the published name and the GitHub page name didn’t match, and the linked repo no longer existed.

Discovered by: Socket.dev; ReversingLabs


9. PACKAGE_SKEW_NOT_UPDATED — npm ip package fix proposed but never released

Check: Source code has new commits not released to package registry.

The npm package ip (~17 million weekly downloads, 278,000+ dependent GitHub repos) had CVE-2024-29415 because its fix for a prior vulnerability was incomplete. A corrective patch was proposed as GitHub PR #144, but the maintainer never published it to npm. In June 2024, the maintainer archived the GitHub repository, making it read-only. The fix exists in source code but has never been released to the registry.

Downstream projects including npm CLI itself, Node-RED, and Alpine Docker images filed issues because they could not get an updated package. Users were advised to switch to alternative packages entirely.

Discovered by: Community security researchers; CVE-2024-29415


10. PACKAGE_STALE_RELEASE — coa npm hijacking (November 2021)

Check: Package has not been released/updated in a long time.

The coa package had ~9 million weekly downloads but hadn’t been legitimately updated in 3+ years. Attackers compromised the maintainer’s account and published malicious versions containing a DanaBot trojan. The stale nature meant fewer eyes were monitoring for suspicious activity. The compromise was first detected when React application CI/CD builds started breaking worldwide. The rc package (~14 million weekly downloads) was hijacked simultaneously.

Discovered by: npm security team; community reports


11. PACKAGE_MALFORMED_DEPENDENCIES — Celery’s pytz (>dev) broke pip worldwide

Check: Package contains dependencies with malformed version specifiers per PEP 508.

Celery versions 4.1.1 through 5.2.0 declared the dependency pytz (>dev), where dev is not a valid PEP 440 version string. This malformed specifier lurked undetected for years because pip’s legacy parser was lenient. When pip 24.1 shipped in mid-2024 with strict PEP 440/508 enforcement, every Celery version from 4.1.1 to 5.2.0 became uninstallable overnight with WARNING: Ignoring version 5.2.0 of celery since it has invalid metadata. CI/CD pipelines worldwide broke.

Bleach 5.0.0 (Mozilla’s HTML sanitizer) shipped with tinycss2 (>=1.1.0<1.2) — a missing comma between version constraints. pip, Poetry, and mach-nix all handled the invalid specifier differently, causing cascading failures.

Discovered by: pip maintainers; Celery community (pip #12793, celery #8001)


12. ARTIFACT_HASH_MISMATCH — Codecov Bash Uploader compromise (January–April 2021)

Check: Downloaded package artifact hash does not match registry-provided hash.

Attackers modified Codecov’s Bash Uploader script on Google Cloud Storage, adding a line that exfiltrated all environment variables from CI environments. The breach went undetected for ~2 months until a customer compared the SHA256 hash of the downloaded script against the hash published on GitHub and found a mismatch. Codecov has 29,000+ enterprise customers including Twilio, HashiCorp, Rapid7, and Atlassian. HashiCorp disclosed its GPG signing key was exposed.

Discovered by: A Codecov customer; subsequently investigated by federal authorities


13. NO_COMMITS — No precisely documented incident

Check: Repository has no commits.

This check targets packages linked to repositories with literally zero commits — empty initialized repos. No well-documented incident precisely matches this condition. In practice, attackers either omit the repository URL entirely (triggering NO_SOURCE_REPO_NOT_FOUND) or create fake repos with at least one commit for plausibility. The closest cases are bulk spam campaigns (e.g., Tea Protocol, February–November 2024, ~613,000–667,000 npm packages) where linked repos contained only a minimal readme and a tea.yaml — functionally empty but technically with 1–2 commits.

The check’s value is as a signal in combination with other indicators: a brand-new package pointing to a zero-commit repo is overwhelmingly likely to be malicious or spam.


14. PACKAGE_DYNAMIC_NAME — ssc-concurrent-log-handler used a variable for its package name

Check: Package name in source code is determined dynamically rather than being a simple string literal.

In September 2023, Phylum documented the malicious PyPI package ssc-concurrent-log-handler as part of a data exfiltration campaign. Its setup.py used a variable for the name parameter rather than a string literal: packagename = "ssc-concurrent-log-handler" → setup(name=packagename, ...). The package’s custom InstallScripts class exfiltrated hostname, IP, username, and home directory contents. The variable-based name is a detection evasion technique — static analysis tools that grep for setup(name="..." miss it.

In March 2024, hundreds of malicious PyPI packages used Fernet-encrypted setup.py files that dynamically constructed C2 URLs by programmatically extracting and appending the package name as a query parameter — severe enough to force PyPI to suspend all new project creation.

Discovered by: Phylum Research; Checkmarx


15. PACKAGE_INSTALL_SCRIPTS — ua-parser-js hijack (October 2021)

Check: Package contains scripts that execute during installation.

Attackers hijacked the npm account of ua-parser-js maintainer Faisal Salman and published versions with a preinstall.js script that installed an XMRig cryptominer on Linux and a password-stealing trojan on Windows. The package has 8 million weekly downloads and 1,200+ direct dependents, including Facebook, Microsoft, Amazon, Google, Slack, and Mozilla. CISA issued an advisory. Just two weeks later, coa and rc were compromised using identical preinstall script techniques.

Discovered by: npm security team; CISA


16. SOURCE_PACKAGE_NAME_UNEXPORTED — 5,943 malicious packages had no real Python module

Check: No package names detected in source code.

On February 23, 2023, Phylum detected a massive automated attack where 5,943+ packages with random two-word names were published to PyPI at a rate of one every 4–8 seconds. Each package contained only a setup.py with a malicious PowerShell command — no actual Python module code, no __init__.py, no proper package name exports. The setup.py served solely as a malware delivery mechanism, downloading executables from Dropbox links.

This pattern has been endemic since February 2021, when dependency confusion spawned thousands of packages containing only minimal setup.py with install hooks but no actual exported module. Sonatype flagged 63,000+ such packages by mid-2022.

Discovered by: Phylum; Sonatype


17. PACKAGE_PAST_MALWARE — colors.js/faker.js sabotage (January 2022)

Check: Package had malware that was subsequently fixed.

Maintainer Marak Squires deliberately sabotaged his packages in protest: colors@1.4.1 got an infinite loop printing “LIBERTY” and Zalgo text, while faker@6.6.6 had all source code removed. Colors has 23 million weekly downloads and ~19,000 dependents; faker had 2.4 million weekly downloads. AWS CDK and thousands of applications broke. npm reverted the packages to safe versions. The community forked faker as @faker-js/faker under community governance.

Discovered by: npm community; npm security team


18. PACKAGE_ACTIVE_MALWARE — event-stream/flatmap-stream (September–November 2018)

Check: Package has unfixed malware.

The attacker “right9ctrl” socially engineered maintainer Dominic Tarr into transferring ownership of event-stream (~2 million weekly downloads), then added flatmap-stream containing encrypted code targeting the Copay Bitcoin wallet. The malware used the target package’s npm description as a decryption key — activating only within Copay’s build environment. It captured wallet credentials for balances >100 BTC or >1,000 BCH. The malicious code was present for ~2.5 months before discovery. npm removed flatmap-stream from the registry entirely.

Discovered by: Community developer @FallingSnow (GitHub issue)


Build Systems and Lockfile Risks

19. SOURCE_UNSUPPORTED_MANIFEST_FILE — Log4Shell hid in shaded JARs invisible to SCA tools

Check: Source repository uses package managers not currently supported for dependency parsing.

After the Log4Shell disclosure (CVE-2021-44228, December 2021), JFrog found ~400 Maven Central packages directly embedded vulnerable Log4j code via class shading or fat JAR inclusion — not declared in pom.xml. In ~65% of cases, Log4j classes were copied and relocated into the package’s own namespace. JFrog stated these “will not be found by tools that look for explicit mentions of library names in the dependency tree.”

A 2025 study by Hopper Security analyzed all 16 million Maven Central artifacts and found 231,000+ packages containing shaded dependencies, hiding 2.5 million vulnerabilities invisible to manifest-based scanning. When Hopper enabled shaded-package scanning for a Fortune 200 company, they uncovered 47% more vulnerabilities previously undetected.

Discovered by: JFrog Security Research; Hopper Security


20. SOURCE_MANIFEST_WITHOUT_LOCKFILE — Dependency confusion exploits (February 2021)

Check: Manifest files without corresponding lockfiles.

Alex Birsan’s research demonstrated that without proper lockfiles and registry configuration, package managers resolve internal package names from public registries. Without a lockfile pinning exact versions and sources, npm install or pip install pulls higher-versioned malicious packages from public registries instead of intended internal ones. The September 2025 “Shai-Hulud” npm attack (affecting 500+ packages) confirmed lockfiles as the primary defense — projects without them automatically pulled malicious versions.

Discovered by: Alex Birsan; Snyk


21. LICENSE_REFERENCE_MISSING_FILE — Lerna bug shipped thousands of npm packages without LICENSE text

Check: License references found without corresponding full license files.

In 2018, a systemic bug in Lerna (the widely-used JavaScript monorepo tool) caused it to not copy the root LICENSE file into individual packages during lerna publish. Babel shipped to npm without LICENSE files despite declaring MIT. Facebook’s react-error-overlay was flagged — the MIT license requires distributing full license text. Dan Abramov acknowledged the omission. Microsoft’s AdaptiveCards packages were similarly affected.

Separately, Lenovo disclosed in 2025 that every Fedora release contains 4–10 packages that declare licenses in metadata but lack license text files. Lenovo must manually remediate this for each laptop preload to satisfy their legal team, delaying Fedora availability on Lenovo hardware.

Discovered by: Lerna community; Lenovo compliance team


22. LICENSE_RESTRICTION_COMMERCIAL — Redis Commons Clause and HashiCorp BSL

Check: License restricts commercial use.

Redis Labs changed several Redis modules from AGPL to “Apache 2.0 modified with Commons Clause” in August 2018, restricting commercial sale. Linux distributions could no longer ship affected modules. In March 2024, Redis re-licensed even core Redis (previously BSD) to dual SSPL/RSALv2, prompting the Linux Foundation to create the Valkey fork within 8 days, backed by AWS, Google, and Oracle. HashiCorp similarly switched Terraform from MPL v2.0 to BSL v1.1 in August 2023, spawning the OpenTofu fork with 140+ company signatories.

Discovered by: Linux Foundation; HashiCorp community


23. LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT — FSF v. Cisco and BusyBox lawsuits

Check: Copyleft license requirements (GPL-style).

The FSF filed its first-ever lawsuit against Cisco Systems in December 2008, alleging Linksys routers contained GPL-licensed software (GCC, GNU Binutils, GNU C Library) without providing required source code — after 5 years of failed compliance negotiations. The settlement required Cisco to make a financial contribution, appoint a Free Software Director, and publish complete source code. The BusyBox GPL lawsuits (2007–2013) targeted Best Buy, Samsung, Verizon, JVC, and Westinghouse. Westinghouse received a default judgment of $90,000 in treble damages plus $47,865 in costs.

Discovered by: FSF; SFLC (Software Freedom Law Center)


24. LICENSE_RESTRICTION_NETWORK_COPYLEFT — iText AGPL forced Belgian government onto obsolete software

Check: License requires sharing modifications when used over network (AGPL-style).

In January 2018, iText founder Bruno Lowagie discovered that Smals — the primary IT integrator for the Belgian Federal Government — had upgraded four government applications to iText 5 (AGPL) without purchasing a commercial license or complying with AGPL’s source-release requirements. Rather than comply, they downgraded to 9-year-old iText 2 or replaced iText with already-end-of-life Adobe LiveCycle. Belgian citizens were served by deliberately downgraded, obsolete software rather than complying with AGPL.

After Apryse acquired iText in 2022, they launched systematic AGPL enforcement. JasperReports deliberately depended on iText 2.1.7 (released 2009) until 2023 — a 14-year-old version with known vulnerabilities — because upgrading would trigger AGPL obligations for all downstream users.

Discovered by: Bruno Lowagie (iText founder); Apryse compliance department


Contributor, Maintenance, and Abandonment Risks

25. SOURCE_FEW_CONTRIBUTORS — core-js maintainer crisis (2019–2023)

Check: Bus factor risk — fewer than threshold unique contributors.

core-js, the most popular JavaScript polyfill library with 43+ million weekly npm downloads and presence on 50%+ of the world’s top 1,000 websites, was maintained essentially by one person: Denis Pushkarev. In November 2019, Pushkarev was sentenced to 18 months in prison. In February 2023, he threatened to shut down or make core-js closed-source, citing $57/month in donations despite the project’s enormous reach.

Discovered by: core-js community


26. FIRST_COMMIT_THIS_YEAR — Dependency confusion newly-created packages (February 2021)

Check: Project is less than 1 year old.

All 200+ packages Alex Birsan published were brand-new, never-before-existing packages on public registries. Each contained preinstall scripts with DNS exfiltration callbacks. The Lazarus Group replicated this pattern in 2024–2025, publishing 234 newly-created malicious npm and PyPI packages, potentially exposing over 36,000 victims.

Discovered by: Alex Birsan; ReversingLabs


27. SOURCE_SINGLE_CONTRIBUTOR — xz utils social engineering (2021–2024)

Check: Single contributor dependency.

XZ Utils was maintained solely by Lasse Collin, experiencing burnout. Starting in 2021, threat actor “Jia Tan” built trust over 2+ years with legitimate contributions. Sock puppet accounts pressured Collin about slow development. Collin eventually granted co-maintainer status. In February 2024, Jia Tan inserted a CVSS 10.0 backdoor enabling unauthorized SSH access. The event-stream incident (2018) followed the same pattern: sole maintainer Dominic Tarr handed over rights to an attacker.

Discovered by: Andres Freund (Microsoft); community analysis


28. LAST_COMMIT_OVER_5_YEARS — Polyfill.io domain takeover (June 2024)

Check: No commits in over 5 years — abandoned project.

Polyfill.io, embedded in 100,000+ websites, was abandoned by its original author. In February 2024, a Chinese company (Funnull) purchased the domain and GitHub account, then modified the CDN to inject malicious JavaScript redirecting mobile users to sports betting and adult content sites. Over 380,000 hosts were affected, including JSTOR, Intuit, World Economic Forum, Hulu, Mercedes-Benz, and WarnerBros.

Discovered by: Sansec; community reports


29. LAST_COMMIT_OVER_A_YEAR — ua-parser-js hijacking (October 2021)

Check: No commits in over 1 year — stale project.

ua-parser-js had relatively infrequent updates when attackers compromised the maintainer’s npm account. CISA’s advisory stated: “Any computer that has this package installed or running should be considered fully compromised.” The package had nearly 1 billion total downloads. This incident directly led to npm mandating 2FA for maintainers of popular packages.

Discovered by: npm security team; CISA


License File and Approval Risks

30. SOURCE_NO_LICENSE — Unlicensed repos block enterprise adoption and M&A

Check: No license file found in source repository.

The npm package electron-to-chromium had a GitHub issue filed by users who stated they “could not use the library” because no LICENSE file existed. Under copyright law, code without a license file defaults to “all rights reserved.”

The Synopsys 2025 OSSRA report found 33% of commercial codebases examined during M&A due diligence contained components with no discernible license in the source repository. FossID documented finding Wappalyzer in multiple client codebases after it went from MIT to GPLv3 to fully private (August 2023, repo deleted), leaving companies with dependencies that had no accessible license provenance at all.

Discovered by: Synopsys Black Duck; FossID


31. LICENSE_MODIFIED — JSON license “shall be used for good, not evil” (2002–present)

Check: License text modified from standard.

Douglas Crockford’s JSON license adds one line to MIT: “The Software shall be used for Good, not Evil.” Google Code stopped hosting JSON-licensed projects (~2009). Google’s Android team rewrote the org.json implementation from scratch. IBM requested a special license grant. In 2016, the Apache Software Foundation banned JSON-licensed software from all Apache products after 8 years of allowing it. Fedora and the FSF classify the license as non-free.

Discovered by: Apache Software Foundation; Google; Fedora


32. LICENSE_NOT_APPROVED — React’s BSD+Patents license forced an ecosystem reckoning

Check: One or more licenses found in repository are not approved.

In July 2017, the Apache Software Foundation classified Facebook’s BSD+Patents license (used by React, Flow, Jest) as Category X — banning React from all Apache projects. On September 15, 2017, WordPress announced it would drop React entirely. One week later, Facebook relicensed React to MIT.

Douglas Crockford’s JSON “Good, Not Evil” license was banned by Google Code (2009), the Apache Foundation (2016), and Fedora. When MongoDB switched to SSPL (October 2018, non-OSI-approved), it was removed from Debian and RHEL repositories and AWS built DocumentDB as an alternative. When Elastic switched to SSPL/ELv2 (January 2021), AWS forked as OpenSearch.

Discovered by: Apache Software Foundation; WordPress/Automattic; Debian


Vulnerability Patterns

33. VULN_HISTORICAL_SEVERE — OpenSSL’s decades of critical CVEs

Check: Critical/High severity vulnerabilities historically reported.

OpenSSL has accumulated hundreds of CVEs from the late 1990s through 2026. Heartbleed (CVE-2014-0160) alone affected ~17% of the Internet’s secure web servers (~500,000) when disclosed in April 2014. Remediation cost exceeded $500M. Log4Shell (CVE-2021-44228, CVSS 10.0) similarly demonstrated chronic vulnerability patterns: the JNDI lookup flaw existed unnoticed since 2013, and CISA estimates it will take at least a decade to find and fix every vulnerable instance.

Discovered by: Google Security (Heartbleed); Alibaba Cloud Security Team (Log4Shell)


34. VULN_RECENT_FREQUENCY — MOVEit Transfer rapid-fire SQLi (May–July 2023)

Check: High frequency of recent vulnerabilities.

Four critical SQL injection CVEs in 5 weeks: CVE-2023-34362 (exploited as zero-day by CL0P ransomware), CVE-2023-35036, CVE-2023-35708, and CVE-2023-36934. CISA estimated 3,000+ US organizations and 8,000+ worldwide were affected, including Shell, BBC, British Airways, and government agencies. Reports suggest CL0P may have possessed the zero-day since July 2021. Each patch revealed additional attack surface.

Discovered by: Progress Software; Mandiant; CISA


35. VULNERABILITIES_LONG_TIME_TO_FIX — Equifax breach via Apache Struts (2017)

Check: Vulnerabilities take longer than threshold to fix.

Apache disclosed CVE-2017-5638 (CVSS 10.0) on March 7, 2017 with a same-day patch. Equifax’s internal scans failed to detect the vulnerability. An expired SSL certificate disabled network monitoring. Attackers exfiltrated data for 76 days. The breach exposed 147 million Americans including Social Security numbers. Cost: $1.38 billion in settlements. The CEO, CIO, and CSO all lost their jobs.

Discovered by: US-CERT; Mandiant (incident response)


36. VULN_UNFIXED — jQuery’s unfixed CVEs across 32% of all codebases

Check: Package has unfixed vulnerabilities.

jQuery is present in 32% of all scanned codebases per the 2025 OSSRA report. 8 of the top 10 high-risk vulnerabilities found were jQuery-related (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023). The jQuery project does not backport fixes to 1.x or 2.x — millions of sites running these end-of-life versions have no available patches. WordPress used jQuery 1.12.4 for years.

Discovered by: Synopsys Black Duck; Snyk


Key Patterns

Three patterns emerge from mapping these 36 checks to real incidents:

  1. Single-maintainer projects are the softest targets. The xz utils, event-stream, and core-js incidents all exploited the same vulnerability — one exhausted developer holding the keys to critical infrastructure.

  2. The gap between source code and published artifacts is weaponized repeatedly. From flatmap-stream’s hidden payload to xz utils’ tarball-only backdoor to Codecov’s modified upload script, attackers consistently exploit the fact that what you audit in Git is not what you install.

  3. Time is the attacker’s greatest ally. Abandoned projects become takeover targets (Polyfill.io), unpatched vulnerabilities become breach vectors (Equifax), and stale packages become hijacking opportunities (coa, rc). The most dangerous risks aren’t exotic — they’re the mundane ones that compound silently.