Packages scanned
8.3M
Coverage npm
registry.npmjs.orgJavaScript / Node.js. Largest registry by package count and the most common supply-chain attack target; the scanner covers preinstall hooks, install-time remote payloads, lifecycle-diff vs prior release, and known-IOC filename matching.
8.3M
222.7K
420.1K
524.7K
10m ago
Install-time attack surface
preinstall / install / postinstall scripts in package.json — run as part of `npm install`
Supported lockfile formats
package-lock.jsonnpm-shrinkwrap.jsonpnpm-lock.yamlyarn.lockSpec format
pkgradar gate --ecosystem npm [email protected]Recent activity
The corpus-wide release feed lives on /campaigns. A per-ecosystem release feed for npm is on the roadmap — the stats above are filtered to this ecosystem in the meantime.
Other ecosystems