Threat Feed

Live stream of malicious and suspicious open-source packages flagged by Nithic's supply-chain analyzer — 200+ static detectors across ten ecosystems: npm, PyPI, crates.io, RubyGems and Go, plus Packagist/PHP, WordPress plugins, VS Code, JetBrains and browser extensions from the Chrome, Edge and Firefox stores. Look up any package.

Verdicts are Nithic's own automated static analysis of publicly published packages, shown for transparency and research. A flag is not a definitive judgment of intent; “suspicious” means risk indicators warrant review. Package names/code are public; no private data is shown.