Research
Suspicious packages we've flagged
We continuously detonate newly-published npm and PyPI packages in an isolated sandbox and score what they actually do. Every package below was flagged as suspicious — its behaviour is consistent with malicious activity. Open any one for the commands it ran and why we flagged it. This is automated analysis and may include false positives.
0
suspicious packages catalogued
No detonations flagged yet.