Open-source package threat intelligence

About ThreatPkg

ThreatPkg is a public threat intelligence dashboard for npm, PyPI, Go, Rust (crates.io), Java (Maven), .NET (NuGet), RubyGems, PHP/Laravel (Packagist), and Dart/Flutter (pub.dev): compromised packages, malicious releases, and advisory identifiers (CVE, GHSA, OSV) in one searchable feed. Incidents are ingested on a regular schedule and attributed to the sources below.

Use the threat feed to scan recent incidents, open a package to review reputation and history, or drill into an incident for full context. Content is aggregated from public advisories with outbound links to original publishers—not auto-generated landing pages for every keyword.

Ecosystems we track

ThreatPkg normalizes supply-chain incidents across these registries in one feed. Each ecosystem uses OSV and GitHub advisory mappings where available; filter the live feed or open package reputation pages when a name appears in an incident.

  • JavaScript and Node.js packages on the npm registry—the most common target for typosquats and postinstall malware in open source.

  • Python packages on PyPI, including wheels and sdists referenced in application and ML dependency trees.

  • Go modules identified by module path; useful for cloud-native and CLI supply-chain monitoring.

  • Rust crates on crates.io with cargo ecosystem advisories from OSV and GitHub.

  • Java and JVM artifacts published to Maven Central and compatible repositories.

  • .NET packages on NuGet for C#, F#, and other CLR ecosystems.

  • RUBYGEMS View feed

    Ruby gems on RubyGems.org with linked GHSA/OSV records where published.

  • PHP packages via Packagist—commonly used for Laravel and Composer dependencies. Incidents link to advisories and affected package names.

  • Dart packages on pub.dev—used by Flutter apps. Track typosquats, compromised releases, and CVE/GHSA identifiers alongside other ecosystems.

Data sources & credits

ThreatPkg aggregates public advisories. Advisory text, identifiers, and severity ratings belong to the original publishers. Links below point to each provider.

  • OSV

    Open Source Vulnerabilities database (npm, PyPI, Go, crates.io, Maven, NuGet, RubyGems, Packagist, Pub).

  • GitHub Advisory Database

    Security advisories published through GitHub.

About me

Built by Akshara Hegde .