npm publish firehose · MITRE ATT&CK

Supply-chain malware, caught at publish.

Every newly published npm package, run through staged sandboxed analysis and classified by MITRE ATT&CK technique, streaming live as it publishes.

Scanned · 24h
62,430
npm publishes analysed
Malware confirmed
11,152
independently corroborated
Caught pre-feed
5,672
before feeds, up to 69d
Exclusive to us
·
not yet on any public feed
ATT&CK techniques
184
distinct, this view

12.91 TB of package code analyzed

detections.stream
last 0
Free

Get alerted on your packages

List up to 50 npm packages you depend on. We'll email you the moment one is confirmed malicious by our triage, often days before it reaches public feeds.

  • Watch up to 50 of your dependencies, every version
  • Confirmed malware only, triage-verified, not raw detector noise
  • Free, double opt-in, one-click unsubscribe

Type to search, Enter or click to add. Not listed? Type the full name and press Enter.

Double opt-in: we email you to confirm. Unsubscribe anytime. No alerts until you confirm.

ATT&CK coverage, live

Each detection is mapped to the techniques its behaviour exhibits. Cells brighten as we observe them across the firehose.

Initial Access
113816
T1195.002 113779
Execution
65860
T1059 52069
T1059.007 15556
Persistence
16599
T1546.016 12305
T1574 429
Defense Evasion
40859
T1027 32750
T1140 17925
T1620 3080
T1480 201
T1036 6564
T1564 403
Credential Access
9450
T1552 318
T1552.001 9039
Discovery
6420
Collection
2994
T1005 2922
Command & Control
27413
T1071 1347
T1071.001 9503
T1571 872
T1105 19800
T1102 1976
Exfiltration
2868
T1041 2321
T1567 743
Impact
107
T1657 21

Confirmed malware, and why

Malicious packages independently corroborated by a public advisory feed, with our sandbox analysis and ATT&CK classification on top. Click any to read the reasoning.

Browse all confirmed advisories →

Full advisory → LWA-2026-10827

An empty module (index.js exports an empty object) with no lifecycle hooks, no dependencies, and no functionality. The package name resembles a legitimate package name. The package appears to be a placeholder or decoy published as part of a broader malicious publishing campaign; no executable payload is present in this version.

analyzed by Leitwacht · first seen 8/8/2026, 9:59:13 AM UTC · analyzed 8/8/2026, 9:59:43 AM UTC
T1195.002 · Compromise Software Supply Chain
Full advisory → LWA-2026-10826
Full advisory → LWA-2026-10824
Full advisory → LWA-2026-10825
Full advisory → LWA-2026-10823
Full advisory → LWA-2026-10822
Full advisory → LWA-2026-10821
Full advisory → LWA-2026-10808
Full advisory → LWA-2026-10815