Latest incident:TanStack + @uipath mini-Shai-Hulud compromise (11 May 2026)
Precursor Threat Intelligence

Check your project forcompromised dependencies

Paste your package-lock.json, pnpm-lock.yaml, yarn.lock, or requirements.txt. See in seconds whether you were exposed to one of 2026's supply-chain compromises.

Everything runs in your browser. Open the Network tab and watch: clicking Scan makes zero requests. Your lockfile never leaves your machine.

36 incidents511 packages tracked across all of them10 ecosystemsData range 15 Sept 2025 11 May 2026Last updated 12 May 2026

Parsed locally in your browser. No upload, no logging, no network round-trip.