Research
Research
Technique write-ups from analysing packages in the sandbox. How something was done, rather than what a particular package did.
Disclosures →
Full technical accounts of individual malicious packages, with the evidence behind each claim.
Package analysis feed →
Every newly published package we detonate and flag, generated automatically.
-
Recovering a deleted npm package from a syscall trace
A package we detonated was deleted from the registry two hours after it was published. We still had the source, because of how npm installs things.