THREATPKG
SYNC STALE

Open-source package threat intelligence

About ThreatPkg

ThreatPkg is a public threat intelligence dashboard for npm, PyPI, Go, Rust (crates.io), Java (Maven), .NET (NuGet), RubyGems, PHP/Laravel (Packagist), and Dart/Flutter (pub.dev): compromised packages, malicious releases, and advisory identifiers (CVE, GHSA, OSV) in one searchable feed. Incidents are ingested on a regular schedule and attributed to the sources below.

Use the threat feed to scan recent incidents, open a package to review reputation and history, or drill into an incident for full context. Content is aggregated from public advisories with outbound links to original publishers—not auto-generated landing pages for every keyword.

Ecosystems we track

ThreatPkg normalizes supply-chain incidents across these registries in one feed. Each ecosystem uses OSV and GitHub advisory mappings where available; filter the live feed or open package reputation pages when a name appears in an incident.

Data sources & credits

ThreatPkg aggregates public advisories. Advisory text, identifiers, and severity ratings belong to the original publishers. Links below point to each provider.

  • OSV

    Open Source Vulnerabilities database (npm, PyPI, Go, crates.io, Maven, NuGet, RubyGems, Packagist, Pub).

  • GitHub Advisory Database

    Security advisories published through GitHub.

About me

Built by Akshara Hegde .