Malicious packages.
Track packages identified as malicious across npm, PyPI, and other software ecosystems. These are supply-chain threats to remove—not vulnerabilities to score or patch.
Latest
LiveRecently published package threats
Loading malicious packages…
Package identity comes first.
Harpia shows the ecosystem, component, version when the source specifies one, advisory identifier, and publication date. Where the source does not provide behavior or a fixed version, the page says so directly.
