Packages scanned
483,634
Coverage npm
registry.npmjs.orgJavaScript / Node.js. Largest registry by package count and the most common supply-chain attack target; the scanner covers preinstall hooks, install-time remote payloads, lifecycle-diff vs prior release, and known-IOC filename matching.
483,634
4,569
53,806
33,483
28s ago
Install-time attack surface
preinstall / install / postinstall scripts in package.json — run as part of `npm install`
Supported lockfile formats
package-lock.jsonnpm-shrinkwrap.jsonpnpm-lock.yamlyarn.lockSpec format
pkgradar gate --ecosystem npm [email protected]Recent activity
The corpus-wide release feed lives on /campaigns. A per-ecosystem release feed for npm is on the roadmap — the stats above are filtered to this ecosystem in the meantime.
Other ecosystems