Check package-lock.json for compromised packages
package-lock.json is the highest-confidence file you can give us. It records the exact version npm installed for every direct and transitive dependency, so a match here is not a guess - it means the compromised version is pinned in your tree.
We check it against 2,969 compromised npm packages drawn from 107 tracked incidents. Everything runs in your browser - your package-lock.json never leaves your machine.
Parsed locally in your browser. Nothing leaves your device, no logging, no network round-trip.
What we read from your package-lock.json
- lockfileVersion 1, 2, and 3 - we detect which you have and read the matching structure
- the flat
packagesmap in v2/v3, including nestednode_modules/a/node_modules/bpaths - the recursive
dependenciestree in v1 - transitive dependencies, not just your direct ones - most compromises arrive several levels deep
Confirmed matches
Because a lockfile pins exact versions, every match is confirmed rather than probable. If we flag something, that specific build really did resolve to a version named in a public advisory.
Things worth knowing about package-lock.json
Transitive dependencies are the whole point
Almost nobody installs a malicious package directly. It arrives as a dependency of a dependency, which is exactly what a lockfile captures and package.json does not. We walk the full tree and tell you the path that pulled it in.
lockfileVersion 2 contains both structures
npm 7+ writes a v2 lockfile with both the legacy dependencies tree and the modern packages map, for backwards compatibility. We read the packages map when present because it is the authoritative one, and fall back to the tree otherwise.
Recent npm compromises we check for
The most recent of 107 tracked incidents affecting this ecosystem.
- GitHub Advisory malware sweep - 2026-08-17 / 2026-08-18 batch (Sui blockchain `@mysten/*` typosquat days 4-5 continuation `sui-move-graphql`+`sui-move-rpc`+`sui-gql-core`+`bcs-core`+`bucket-protocol-sdk-v2`, Tinkoff BNPL dep-confusion tail `bnpl-blocks-independent-bnpl-search`, LEB128 encoding typosquat pair `leb128x`+`ulebkit`, generic CWE-506 boilerplate `blastradar`+`runtime-health`, PyPI `socks5901` Android `/sdcard/` Telegram-bot exfiltrator)
- GitHub Advisory quiet-tail sweep - 2026-08-16 / 2026-08-17 (`@ai-vertical/ai-agent` npm generic-malware + `kb-ai` PyPI OpenSSF `setup.py`-install pentest dep-confusion demo)
- GitHub Advisory npm CWE-506 sweep - 2026-08-15 batch (`@velliajs/discord` `discord.js` impersonator with hardcoded GitHub PAT + hidden `_verifyAuthorization` kill-switch, `akamai(js)-sensor` Google-Calendar invisible-Unicode C2 trio, HackerOne/Twilio `*-probe`/`*-poc` bug-bounty-canary droppers with live payloads, `depcruise-*` + `gunzip-js` `99.9.1` dependency-confusion canary, `@wololasod/tiny-id` RC4 Windows/Linux dropper, `@finaxis/common-js` Xelis miner, `*-vim` naming-canary pair, plus IP/webhook exfiltrators)
- GitHub Advisory npm CWE-506 sweep - 2026-08-14 batch (~27 packages: `jchunt.top` telemetry-canary day-2 `xrblocks-mcp`, `preinstall-hook-webhook-callback-demo` webhook.site demo, `@secauditb20y/sec-test-r3b` self-labeled sec-test POC, `webautomation_js` + `@ferudionz/*` obfuscator.io RC4 runtime exfil trio, `@guangnao/agent-proxy` Claude/Codex credential monetizer to `hub.client-llm.com`, `@lodash-js/lodash-js` Xelis miner, `@divineubg/divine` ntfy.sh EventSource C2, `@demopack/www` iOS iframe exploit injector, `@ghost_debugger/nanocache` hidden Windows binary launcher, `datefmt-simple-utils` reverse shell to `8.135.48.40:4444`, `registrynpmjs.to` typosquat cluster (`@polymarkets/clob-client-v2`, `@devmikets/hyperliquid-sdk`), Brazilian `alelo-*` dep-confusion cluster to `209.99.185.109`, plus `@peptideventure/*`, `@mexc/shared-utils`, `sui-gql-lite`, `bcs-mini`)
- GitHub Advisory npm CWE-506 sweep - 2026-08-13 batch (`ltidisafe` GCS dep-confusion dropper ring `check-audit`+`cspell-esm`+`eslint-publish-release`+`in-install`+`knip-bun`+`resolve-audit`+`napi-raw`, `31.97.137.157:45000` bare-IP Chromium-DPAPI stealer kit `vexium-kit`+`ventra-kit`+`velora-kit`+`vortex-kit`+`copytrade-core`+`prediction-trader`, `@hzero-front-ui/*` internal-scope dep-confusion 5-package cluster with `callback.m0chan.co.uk` DNS+HTTPS beacon, `@khaznatech/*` webhook.site preinstall exfil 3-pack, `jchunt.top` telemetry-canary series `wct-st`+`tizen-webdriver-cli`, `8.135.48.40:4444` reverse-shell date-fmt masquerade pair `datefmt-util-helper`+`date-fmt-helper-xz`, `notafollower` AWS IMDSv2 credential theft, `bs58-15` base58 typosquat via `base65-15x` transitive, `@solana-js/web3` Windows PowerShell + `files.catbox.moe` RCE, `postcss-initialize-plugin` Ethereum-RPC-C2 continuation, `mutex-forge` Telegram+Slack+Ethereum-Sepolia RAT, `chai-as-reformed`+`process-live-log`+`external-process-live-log`+`minimalistic-assert-plus` Function-constructor R-shell family, `node-config-svg-contract` eval-from-URL, `nc-verify-127942`+`@jacksher/install-exec-poc` OAST recon POCs, `cilm-ui-commons` pipedream.net preinstall, ~10 boilerplate CWE-506)
- GitHub Advisory npm CWE-506 sweep - 2026-08-12 batch (Web3 typosquat webhook.site ring day-2 `permit2`+`camelot-ammv2-*`+`boring-vault`+`augustdigital-sdk`+`upshift-*`, Ethereum-RPC-C2 `envpack-conf`+`tailwind-form-templates` XOR-encrypted second-stage on blockchain, `svelte-kit-vim`+`kit-map-vim` map-streak-kit day-4 continuation, `sui-gql`+`bcs-compact` Sui `@mysten/*` typosquat continuation, ~50-package `@years17/18/19/20/*` n8n-nodes-utils-helper red-team SSH-backdoor mass drop, `internallib_v756`/`v392` bare `/dev/tcp/10.0.74.63/4444` reverse shell, `mcp-util-helpers` webhook.site R-shell channel, `passkeys-react` Burp Collaborator OAST recon, `bb-twl-k7x2` Twilio-internal dep-confusion, `@telekom-ods/react-ui-kit` Deutsche Telekom internal-scope, `verify-cli`+`@assetshop/verify-cli` OAST recon pair, `dakumangalsingh` Java-Robot RAT with jpackage wrapper, boilerplate CWE-506 mass npm flood ~100 packages)
- GitHub Advisory npm CWE-506 sweep - 2026-08-11 batch (webhook.site Web3 typosquat credential-theft ring `@openzeppelin-4/5/contracts`+`@aerodrome-finance/contracts`+`@aerodrome-finance/slipstream`+`ethereum-vault-connector`, `safe-local-env-loader` env-local RAT sibling, `newtun` unencrypted-WebSocket PTY RAT with self-update, `svelte-vim-kit`+`kit-vim-map` map-streak-kit family continuation, `@nzeros/codebreak` Go ELF disguised as C solver, `base65-*` base-x typosquat cluster with 123KB obfuscated payload + `bs58-*` boilerplate siblings, coordinated `oastify.com`/`sslip.io`/webhook OAST dep-confusion recon beacons)
- GitHub Advisory npm CWE-506 sweep - 2026-08-10 batch (`iconova-react` + `postcss-initial-provider` on-chain Ethereum RPC dead-drop C2 loader pair, `svelte-kit-streak`+`kit-map-streak` Linux implant continuation of the map-streak-kit family, `@rblxts/services` catbox.moe Windows RAT sibling of last week's `@rbx-ts/services`, `@kuperka/chainguard-sdk` browser-form + wallet exfil, `xerohub-discord-voice` Discord-token stealer, `env-local` Windows persistent screen-capture + remote control, `hex-encode-utils` Cloudflare-Workers AES-GCM Python-payload loader, `cryptostock`/`tokocrytodev` Infura wallet-drainer, `simple-date-formatter-new-9/10` bash reverse shell to 124.221.154.135:4444, `polymarket-stake-mathss` log-taker.store loader, `chai-tracker` chai-spies impersonator with `dbconnectify` C2, `@noobaihome/amis-*-area-widget` Baidu-internal dep-confusion SSRF probe, and multi-vendor SQLite/postcss/commonjs/eth-library typosquat clusters)
package-lock.json security questions
- Does npm audit already catch this?
npm auditchecks your tree against the GitHub Advisory Database for vulnerabilities - bugs in legitimate packages. It is much weaker on malware: packages published deliberately to steal credentials. Those are usually removed from the registry within hours, and once the package is gone,npm auditfrequently reports nothing at all even though the malicious version is still pinned in your lockfile and still sitting in your CI cache. That gap is what this tool covers.- Is my lockfile uploaded anywhere?
- No. The parsing and matching both run in your browser as JavaScript. Your lockfile is never sent to our servers, and there is no request containing its contents. You can confirm this by opening your browser devtools network tab while you run a scan.
- What should I do if it finds something?
- Treat the host as compromised rather than just bumping the version. Most of these packages run code at install time, so by the time you notice, the payload has already executed with your environment variables in scope. Rotate credentials from a different machine, then pin to a safe version and clear your CI and private-registry caches - mirrors routinely keep serving tarballs after the public registry has pulled them.
- My package-lock.json is huge. Will it still work?
- Yes. We handle files up to 12 MB, which comfortably covers monorepo lockfiles with tens of thousands of entries. Nothing is uploaded, so size only affects how long your own browser takes - usually well under a second.
Check another file
We only list package versions named by the original advisory - we don't infer compromises. Spotted one we're missing? Send it in.