back
Supply Chain Intelligence
Malicious package & supply-chain intelligence — powered by OpenSSF, OSV, and depx. Check if a package is known-malicious, browse the OSSF directory, or scan GitHub repos.
Package Verdict Checker
Check if a specific package is known-malicious. Enter a package name or use ecosystem:package format.
OSSF Malicious Packages
0 packages⏳ Loading npm packages…
Source: ossf/malicious-packages