Every newly published npm package, run through staged sandboxed analysis and classified by MITRE ATT&CK technique, streaming live as it publishes.
12.91 TB of package code analyzed
List up to 50 npm packages you depend on. We'll email you the moment one is confirmed malicious by our triage, often days before it reaches public feeds.
Each detection is mapped to the techniques its behaviour exhibits. Cells brighten as we observe them across the firehose.
Malicious packages independently corroborated by a public advisory feed, with our sandbox analysis and ATT&CK classification on top. Click any to read the reasoning.
Browse all confirmed advisories →
An empty module (index.js exports an empty object) with no lifecycle hooks, no dependencies, and no functionality. The package name resembles a legitimate package name. The package appears to be a placeholder or decoy published as part of a broader malicious publishing campaign; no executable payload is present in this version.