Detection publication & takedown policy
Version 1.0 · Effective 2026-06-11 · Last updated 2026-06-11
This policy is non-exhaustive: the absence of a package from our surfaces does not mean it is safe. Coverage is currently npm-focused and automated.
What we publish
We name a package version as malicious in public only when both hold:
- 1. First-hand evidence. We captured and analysed the package and hold concrete evidence of malicious behaviour (observed exfiltration endpoints, credential-harvesting code, obfuscated droppers, install-script execution).
- 2. Independent confirmation. Beyond a single automated pass, the finding is confirmed in one of two ways before we name it publicly: (a) an independent malware-intelligence source has also identified the same package version as malicious (for example the OpenSSF Malicious Packages project / OSV, a GitHub Security Advisory, or another reputable feed; where publicly citable we link it, otherwise we state that corroboration exists without naming a feed we cannot redistribute); or (b) a second, independent review of the evidence by a stronger model, prompted to disprove the finding, still concludes it is malicious. We never name a package publicly on a single automated judgment alone.
Naming a package as malicious on our public detections page requires both conditions above; a novel catch we have not yet seen corroborated is not named there until it is. This is a publication threshold for that page, not a commitment to keep our research private: we publish our findings and may share detections through community datasets such as OSV and any feed we offer. We do not publish leaked secrets. We do not speculatively attribute attacks to named real-world individuals (publishing and authorship identities are forgeable), but where the evidence supports it we may identify a publishing account or source already associated with malicious packages, such as a repeat offender or a coordinated campaign.
How we describe findings
We state observed facts and indicators drawn from our evidence ("the package contacted this host", "the install script executed this command"), not unprovable characterisations. Live claims are anchored to a timestamp in UTC. Because we publish only versions an independent source has already identified as malicious (and such versions are frequently already removed from the registry), we do not delay publication for individual maintainer notice; anyone can request a takedown at any time.
Accuracy, corrections and withdrawal
Detection is probabilistic and mistakes are possible. If we learn that a published finding is wrong or no longer supported, we withdraw or correct it promptly. A withdrawal is a soft retraction that preserves an audit trail, not a silent deletion. We correct our own surfaces and, where the record was contributed to an external project such as OSV, submit the corresponding upstream withdrawal. We cannot guarantee that third-party caches or downstream consumers erase the original.
Request a takedown or correction
Anyone may ask us to remove or correct a finding. You do not have to be the package owner. Use the form below and give us sufficient reasons or evidence that the finding is wrong, for example: the flagged behaviour is legitimate, it is a false positive, or the version has been removed or superseded.
We aim to acknowledge promptly (ordinarily within a few business days), review the request in good faith against our retained analysis records, and respond. We are a small team; these are good-faith targets, not guarantees. We withdraw or correct anything that is not supportable, at no charge. Where a finding was previously corrected the underlying sample may have been purged, so review relies on our retained records rather than the original bytes.
A request does not by itself cause a finding to be withdrawn: we act on the merits and the evidence, and may decline to act on, or limit our response to, abusive, automated, or repetitive submissions, or submissions that appear intended to suppress an accurate finding.
Data protection and privacy
Operating the takedown and waitlist forms involves personal data, and indicators of compromise drawn from samples may incidentally contain personal data.
- What we collect: takedown requests (package details, the basis you provide, and an optional stated role) and the contact email you supply; waitlist sign-ups collect a contact email. We may retain limited technical metadata such as timestamps and anti-abuse signals.
- Purpose: to operate a defensive security service, triage and respond to requests, correct findings, communicate with you, and prevent abuse of the forms.
- Legal basis: our legitimate interest in operating a defensive security service, and your consent where you have opted in (for example the waitlist).
- Minimisation: we collect only what we need to handle your request. We do not publish leaked credentials or other secrets, and we do not speculatively name real-world individuals as attackers (we may identify a repeat-offending publishing account from registry evidence).
- Retention: personal data is retained for up to 24 months and then deleted or anonymised, except where we keep a minimal correction or audit record.
- Your rights: subject to applicable law you may request access to, correction of, or erasure of your personal data, and may object to certain processing. Contact privacy@leitwacht.eu.
The data controller is LeitWacht (Pty) Ltd, a South African company. We aim to handle personal data consistently with both the EU General Data Protection Regulation (GDPR) and the South African Protection of Personal Information Act (PoPIA). For any privacy question, contact privacy@leitwacht.eu.
No warranty and liability
Published findings are provided "as is", in good faith, for defensive and informational purposes, without warranty of any kind, express or implied. Nothing in this policy or on our surfaces creates any relationship or duty of care between Leitwacht and any reader or user, and the service is intended for professional / business use.
To the fullest extent permitted by applicable law, LeitWacht (Pty) Ltd accepts no liability for any loss or damage arising from or in connection with a published finding or your use of, or reliance on, this service. We do not rely on this disclaimer in place of accuracy: the evidence, corroboration, and correction controls described above are our primary safeguards, and we correct mistakes promptly and in good faith.
This policy and our services are governed by the laws of the Republic of South Africa.
Records we distribute as a feed will be offered under a permissive open licence (to be finalised) and are derived from our own detections and permissively-licensed corroboration only. The permissive-lineage commitment applies to the redistributed or contributed feed, not necessarily to this display surface.
General contact: hello@leitwacht.eu · Security and takedowns: security@leitwacht.eu · Privacy: privacy@leitwacht.eu
Leitwacht Threat Intel · back to live detections