Since Sonatype began tracking malicious open source packages in 2017, we have logged nearly 2 million malicious packages.
Data: CISA KEV Catalog, NVD (NIST). Both are U.S. Government public-domain feeds. Not security advice.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results