Research
Packages worth a second look
We continuously detonate newly-published npm and PyPI packages in an isolated sandbox and record what they actually do. Two kinds of entry appear below. Flagged means the observed behaviour is consistent with malicious activity. Notable means the package did something an install was not asked to do — writing into your AI agent's instruction files, say — which is worth knowing about even when the package is entirely legitimate; those are not classified as malicious. Open any entry for what it ran and what we observed. This is automated analysis and may include false positives.
4
packages catalogued
Updated 2026-08-29 · JSON feed · sitemap
Where a finding warrants a full technical account, we publish one — see disclosures.