Every newly published npm package, run through staged sandboxed analysis and classified by MITRE ATT&CK technique, streaming live as it publishes.
All counts are npm package versions. Confirmed: we classified it malicious and an external feed lists it too. Pre-feed: a feed lists it, and our detectors flagged it before the feed did. Exclusive: we confirmed it and no feed lists it yet. A version gets a public advisory only once its verdict has a written analysis, so the advisory index is smaller.
26.96 TB of package code analyzed
List up to 50 npm packages you depend on. We'll email you the moment one is confirmed malicious by our triage, often days before it reaches public feeds.
Each detection is mapped to the techniques its behaviour exhibits. Cells brighten as we observe them across the firehose.
Malicious packages independently corroborated by a public advisory feed, with our sandbox analysis and ATT&CK classification on top. Click any to read the reasoning.
Browse all confirmed advisories →
css-flow-render-shim@1.0.0 ships a bundled payload (package/payload.bundle.min.js) that executes when the module is required. It first deletes matching entries from require.cache (paths containing "payload", "rb_wixui", "rb_dsgnsys") to conceal its presence, then collects host reconnaissance by spawning child processes: whoami, id, uname -a, `env | head -100`, ifconfig / ip addr, and `cat /etc/hosts`. Each command's output is sent as a query string to the hardcoded collector hxxps://webhook[.]site/69bcd627-1871-4dda-b880-83b37ceac418 (via fetch() with an https.get() fallback), together with the hostname, Node version, platform, pid and the package name. The environment dump can carry credentials and tokens present in the installer's environment. The remainder of the file is a Proxy-based stub exporting fake Wix thunderbolt registry names (thunderboltRegistry, corvidRegistry, editorRegistry, etc.) to make the package resemble a CSS/render shim; the declared entry point index.js is an empty module, so the payload is reached by requiring payload.bundle.min.js directly. IOCs: C2 hxxps://webhook[.]site/69bcd627-1871-4dda-b880-83b37ceac418 (host webhook[.]site, port 443).