Check pnpm-lock.yaml for compromised packages
pnpm-lock.yaml pins the exact version of every package in your store, including the full transitive graph, so it gives a confirmed answer. We support both the v6 and v9 lockfile layouts.
We check it against 2,969 compromised npm packages drawn from 107 tracked incidents. Everything runs in your browser - your pnpm-lock.yaml never leaves your machine.
Parsed locally in your browser. Nothing leaves your device, no logging, no network round-trip.
What we read from your pnpm-lock.yaml
- v6 layout - a single
packagesmap with/name/versionkeys - v9 layout - split
packagesandsnapshotsmaps withname@versionkeys importers, so we can tell your direct dependencies apart from transitive ones- peer-resolution suffixes such as
name@1.2.3(react@18.3.1), which we strip back to the real version
Confirmed matches
pnpm lockfiles pin exact resolved versions, so every match is confirmed rather than probable.
Things worth knowing about pnpm-lock.yaml
Workspaces are covered
In a pnpm monorepo the root lockfile carries every workspace package under importers. Pasting the single root pnpm-lock.yaml therefore checks the whole repo at once - you do not need to scan each package separately.
The content-addressable store does not protect you
pnpm’s store deduplicates by content hash, which is excellent for disk usage but has no bearing on whether the content is malicious. A compromised version hashes and stores exactly like a clean one.
Recent npm compromises we check for
The most recent of 107 tracked incidents affecting this ecosystem.
- GitHub Advisory malware sweep - 2026-08-17 / 2026-08-18 batch (Sui blockchain `@mysten/*` typosquat days 4-5 continuation `sui-move-graphql`+`sui-move-rpc`+`sui-gql-core`+`bcs-core`+`bucket-protocol-sdk-v2`, Tinkoff BNPL dep-confusion tail `bnpl-blocks-independent-bnpl-search`, LEB128 encoding typosquat pair `leb128x`+`ulebkit`, generic CWE-506 boilerplate `blastradar`+`runtime-health`, PyPI `socks5901` Android `/sdcard/` Telegram-bot exfiltrator)
- GitHub Advisory quiet-tail sweep - 2026-08-16 / 2026-08-17 (`@ai-vertical/ai-agent` npm generic-malware + `kb-ai` PyPI OpenSSF `setup.py`-install pentest dep-confusion demo)
- GitHub Advisory npm CWE-506 sweep - 2026-08-15 batch (`@velliajs/discord` `discord.js` impersonator with hardcoded GitHub PAT + hidden `_verifyAuthorization` kill-switch, `akamai(js)-sensor` Google-Calendar invisible-Unicode C2 trio, HackerOne/Twilio `*-probe`/`*-poc` bug-bounty-canary droppers with live payloads, `depcruise-*` + `gunzip-js` `99.9.1` dependency-confusion canary, `@wololasod/tiny-id` RC4 Windows/Linux dropper, `@finaxis/common-js` Xelis miner, `*-vim` naming-canary pair, plus IP/webhook exfiltrators)
- GitHub Advisory npm CWE-506 sweep - 2026-08-14 batch (~27 packages: `jchunt.top` telemetry-canary day-2 `xrblocks-mcp`, `preinstall-hook-webhook-callback-demo` webhook.site demo, `@secauditb20y/sec-test-r3b` self-labeled sec-test POC, `webautomation_js` + `@ferudionz/*` obfuscator.io RC4 runtime exfil trio, `@guangnao/agent-proxy` Claude/Codex credential monetizer to `hub.client-llm.com`, `@lodash-js/lodash-js` Xelis miner, `@divineubg/divine` ntfy.sh EventSource C2, `@demopack/www` iOS iframe exploit injector, `@ghost_debugger/nanocache` hidden Windows binary launcher, `datefmt-simple-utils` reverse shell to `8.135.48.40:4444`, `registrynpmjs.to` typosquat cluster (`@polymarkets/clob-client-v2`, `@devmikets/hyperliquid-sdk`), Brazilian `alelo-*` dep-confusion cluster to `209.99.185.109`, plus `@peptideventure/*`, `@mexc/shared-utils`, `sui-gql-lite`, `bcs-mini`)
- GitHub Advisory npm CWE-506 sweep - 2026-08-13 batch (`ltidisafe` GCS dep-confusion dropper ring `check-audit`+`cspell-esm`+`eslint-publish-release`+`in-install`+`knip-bun`+`resolve-audit`+`napi-raw`, `31.97.137.157:45000` bare-IP Chromium-DPAPI stealer kit `vexium-kit`+`ventra-kit`+`velora-kit`+`vortex-kit`+`copytrade-core`+`prediction-trader`, `@hzero-front-ui/*` internal-scope dep-confusion 5-package cluster with `callback.m0chan.co.uk` DNS+HTTPS beacon, `@khaznatech/*` webhook.site preinstall exfil 3-pack, `jchunt.top` telemetry-canary series `wct-st`+`tizen-webdriver-cli`, `8.135.48.40:4444` reverse-shell date-fmt masquerade pair `datefmt-util-helper`+`date-fmt-helper-xz`, `notafollower` AWS IMDSv2 credential theft, `bs58-15` base58 typosquat via `base65-15x` transitive, `@solana-js/web3` Windows PowerShell + `files.catbox.moe` RCE, `postcss-initialize-plugin` Ethereum-RPC-C2 continuation, `mutex-forge` Telegram+Slack+Ethereum-Sepolia RAT, `chai-as-reformed`+`process-live-log`+`external-process-live-log`+`minimalistic-assert-plus` Function-constructor R-shell family, `node-config-svg-contract` eval-from-URL, `nc-verify-127942`+`@jacksher/install-exec-poc` OAST recon POCs, `cilm-ui-commons` pipedream.net preinstall, ~10 boilerplate CWE-506)
- GitHub Advisory npm CWE-506 sweep - 2026-08-12 batch (Web3 typosquat webhook.site ring day-2 `permit2`+`camelot-ammv2-*`+`boring-vault`+`augustdigital-sdk`+`upshift-*`, Ethereum-RPC-C2 `envpack-conf`+`tailwind-form-templates` XOR-encrypted second-stage on blockchain, `svelte-kit-vim`+`kit-map-vim` map-streak-kit day-4 continuation, `sui-gql`+`bcs-compact` Sui `@mysten/*` typosquat continuation, ~50-package `@years17/18/19/20/*` n8n-nodes-utils-helper red-team SSH-backdoor mass drop, `internallib_v756`/`v392` bare `/dev/tcp/10.0.74.63/4444` reverse shell, `mcp-util-helpers` webhook.site R-shell channel, `passkeys-react` Burp Collaborator OAST recon, `bb-twl-k7x2` Twilio-internal dep-confusion, `@telekom-ods/react-ui-kit` Deutsche Telekom internal-scope, `verify-cli`+`@assetshop/verify-cli` OAST recon pair, `dakumangalsingh` Java-Robot RAT with jpackage wrapper, boilerplate CWE-506 mass npm flood ~100 packages)
- GitHub Advisory npm CWE-506 sweep - 2026-08-11 batch (webhook.site Web3 typosquat credential-theft ring `@openzeppelin-4/5/contracts`+`@aerodrome-finance/contracts`+`@aerodrome-finance/slipstream`+`ethereum-vault-connector`, `safe-local-env-loader` env-local RAT sibling, `newtun` unencrypted-WebSocket PTY RAT with self-update, `svelte-vim-kit`+`kit-vim-map` map-streak-kit family continuation, `@nzeros/codebreak` Go ELF disguised as C solver, `base65-*` base-x typosquat cluster with 123KB obfuscated payload + `bs58-*` boilerplate siblings, coordinated `oastify.com`/`sslip.io`/webhook OAST dep-confusion recon beacons)
- GitHub Advisory npm CWE-506 sweep - 2026-08-10 batch (`iconova-react` + `postcss-initial-provider` on-chain Ethereum RPC dead-drop C2 loader pair, `svelte-kit-streak`+`kit-map-streak` Linux implant continuation of the map-streak-kit family, `@rblxts/services` catbox.moe Windows RAT sibling of last week's `@rbx-ts/services`, `@kuperka/chainguard-sdk` browser-form + wallet exfil, `xerohub-discord-voice` Discord-token stealer, `env-local` Windows persistent screen-capture + remote control, `hex-encode-utils` Cloudflare-Workers AES-GCM Python-payload loader, `cryptostock`/`tokocrytodev` Infura wallet-drainer, `simple-date-formatter-new-9/10` bash reverse shell to 124.221.154.135:4444, `polymarket-stake-mathss` log-taker.store loader, `chai-tracker` chai-spies impersonator with `dbconnectify` C2, `@noobaihome/amis-*-area-widget` Baidu-internal dep-confusion SSRF probe, and multi-vendor SQLite/postcss/commonjs/eth-library typosquat clusters)
pnpm-lock.yaml security questions
- Which pnpm lockfile versions are supported?
- v6 and v9, which between them cover pnpm 8 and 9 onwards. The two use noticeably different key shapes, so we detect the layout and read whichever applies rather than assuming one.
- Do I need to scan every workspace in my monorepo?
- No. The root pnpm-lock.yaml already contains the resolved graph for all workspace packages, so one paste covers everything.
- Does pnpm’s stricter node_modules layout prevent supply-chain attacks?
- It prevents phantom dependencies - code importing packages it never declared. That is a genuine robustness win, but it does nothing about a package you did declare being compromised, or a transitive dependency of it being compromised. That is what this checks.
Check another file
We only list package versions named by the original advisory - we don't infer compromises. Spotted one we're missing? Send it in.