PkgRadar

About

We catch supply-chain malware before the world names it.

PkgRadar statically scans every new release across nine package registries, gates it in your CI, and publishes the receipts — so a compromised dependency is blocked before it ever reaches a build, often days before the public advisory exists.

What we do

We treat every package as hostile data. PkgRadar unpacks and analyzes new releases — code, manifests, and install hooks — without ever running them, scores the result, and returns a block / review / pass verdict your pipeline can gate on in one line. We correlate related malicious releases into campaigns and surface the whole thing on a public intelligence feed.

Why we built it this way

Static-only analysis is a deliberate choice: it lets us inspect malware safely, at registry scale, on day zero — no sandbox, no execution, no waiting for someone else to get burned first. That's how we flag a large share of malicious packages beforetheir public OSV advisory exists. We're precision-first: a gate that cries wolf gets turned off, so we publish our precision and recall openly and never ship a detector change that adds a false positive. See the detection methodology and our live coverage and lead-time for the full picture.

Who's behind it

PkgRadar is built and operated by Zenofex LLC, an independent security company. More about the team and our other work is at zenofex.com.

Talk to us

Ready to try it? Start free — 25 scans a month, no card.