Is this package compromised?
Track malicious releases, account takeovers, typosquatting, dependency confusion, and worms.
Active issues (7d)
Incidents (90d)
Less More
Volume by ecosystem (30d)
PyPI
npm
Go
Reported packages
| Package | Ecosystem | Status | Attack Type | ||
|---|---|---|---|---|---|
| @lightdash/cli | npm | Compromised | Malicious version | 1 | 11d ago |
| @usebruno/cli | npm | Compromised | Script abuse | 1 | 11d ago |
| telnyx | pypi | Compromised | Malicious version | 1 | 14d ago |
| litellm | pypi | Compromised | Other | 1 | 19d ago |
| github.com/aquasecurity/trivy | go | Compromised | Typosquatting | 1 | 20d ago |
| dydx-v4-client | pypi | Compromised | Malicious version | 1 | 66d ago |
| is-arrayish | npm | Compromised | Account takeover | 1 | 209d ago |
| error-ex | npm | Compromised | Account takeover | 1 | 209d ago |
| color-convert | npm | Compromised | Account takeover | 1 | 209d ago |
| color-name | npm | Compromised | Account takeover | 1 | 209d ago |
| debug | npm | Compromised | Account takeover | 1 | 209d ago |
| color | npm | Compromised | Account takeover | 1 | 209d ago |
| color-string | npm | Compromised | Account takeover | 1 | 209d ago |
| simple-swizzle | npm | Compromised | Account takeover | 1 | 209d ago |
| backslash | npm | Compromised | Account takeover | 1 | 209d ago |
| @metamask/sdk-react | npm | Compromised | Malicious version | 1 | 210d ago |
| @metamask/sdk | npm | Compromised | Malicious version | 1 | 210d ago |
| @metamask/sdk-communication-layer | npm | Compromised | Malicious version | 1 | 210d ago |
| prebid-universal-creative | npm | Compromised | Other | 1 | 214d ago |
| prebid.js | npm | Compromised | Malicious version | 1 | 214d ago |
Live feed
Axios Compromise on npm Introduces Hidden Malicious Package
Incident 13d ago
Sonatype Discovers Two Malicious npm Packages
Incident 24d ago