Monitoring npm in real-time

Supply chain
security for npm

Watches popular packages for suspicious code changes and alerts you before you install.

01

Watch

Polls the npm registry every 5 minutes for new package versions

02

Scan

Diffs the code and runs AST analysis for known attack patterns

03

Alert

Flags suspicious changes and auto-posts to Twitter

Packages monitored
Scans today
Alerts triggered

Recent scans

Live