Check yarn.lock for compromised packages
yarn.lock records the exact version Yarn resolved for every dependency in your tree, so a match is confirmed rather than probable. We read both Yarn Classic (v1) and Yarn Berry lockfiles.
We check it against 2,969 compromised npm packages drawn from 107 tracked incidents. Everything runs in your browser - your yarn.lock never leaves your machine.
Parsed locally in your browser. Nothing leaves your device, no logging, no network round-trip.
What we read from your yarn.lock
- Yarn Classic (v1) entries -
"pkg@^1.0.0":followed by aversionfield - Yarn Berry entries, including the
__metadatablock, which we skip - multi-specifier keys, where several ranges share one resolved entry
- scoped packages, resolved back to their real
@scope/name
Confirmed matches
Because yarn.lock pins resolved versions, every match is confirmed. If we flag something, that version really is what Yarn installed.
Things worth knowing about yarn.lock
Berry and Classic are both handled
The two formats differ enough to break naive parsers, so we use Yarn's own syntax parser rather than a regex. You do not need to tell us which one you have - paste it and we detect it.
One resolution, many requesters
Yarn deduplicates, so a single entry often satisfies several different ranges requested by different parts of your tree. We dedupe on name and version so a widely-shared compromised package is reported once rather than a dozen times.
Recent npm compromises we check for
The most recent of 107 tracked incidents affecting this ecosystem.
- GitHub Advisory malware sweep - 2026-08-17 / 2026-08-18 batch (Sui blockchain `@mysten/*` typosquat days 4-5 continuation `sui-move-graphql`+`sui-move-rpc`+`sui-gql-core`+`bcs-core`+`bucket-protocol-sdk-v2`, Tinkoff BNPL dep-confusion tail `bnpl-blocks-independent-bnpl-search`, LEB128 encoding typosquat pair `leb128x`+`ulebkit`, generic CWE-506 boilerplate `blastradar`+`runtime-health`, PyPI `socks5901` Android `/sdcard/` Telegram-bot exfiltrator)
- GitHub Advisory quiet-tail sweep - 2026-08-16 / 2026-08-17 (`@ai-vertical/ai-agent` npm generic-malware + `kb-ai` PyPI OpenSSF `setup.py`-install pentest dep-confusion demo)
- GitHub Advisory npm CWE-506 sweep - 2026-08-15 batch (`@velliajs/discord` `discord.js` impersonator with hardcoded GitHub PAT + hidden `_verifyAuthorization` kill-switch, `akamai(js)-sensor` Google-Calendar invisible-Unicode C2 trio, HackerOne/Twilio `*-probe`/`*-poc` bug-bounty-canary droppers with live payloads, `depcruise-*` + `gunzip-js` `99.9.1` dependency-confusion canary, `@wololasod/tiny-id` RC4 Windows/Linux dropper, `@finaxis/common-js` Xelis miner, `*-vim` naming-canary pair, plus IP/webhook exfiltrators)
- GitHub Advisory npm CWE-506 sweep - 2026-08-14 batch (~27 packages: `jchunt.top` telemetry-canary day-2 `xrblocks-mcp`, `preinstall-hook-webhook-callback-demo` webhook.site demo, `@secauditb20y/sec-test-r3b` self-labeled sec-test POC, `webautomation_js` + `@ferudionz/*` obfuscator.io RC4 runtime exfil trio, `@guangnao/agent-proxy` Claude/Codex credential monetizer to `hub.client-llm.com`, `@lodash-js/lodash-js` Xelis miner, `@divineubg/divine` ntfy.sh EventSource C2, `@demopack/www` iOS iframe exploit injector, `@ghost_debugger/nanocache` hidden Windows binary launcher, `datefmt-simple-utils` reverse shell to `8.135.48.40:4444`, `registrynpmjs.to` typosquat cluster (`@polymarkets/clob-client-v2`, `@devmikets/hyperliquid-sdk`), Brazilian `alelo-*` dep-confusion cluster to `209.99.185.109`, plus `@peptideventure/*`, `@mexc/shared-utils`, `sui-gql-lite`, `bcs-mini`)
- GitHub Advisory npm CWE-506 sweep - 2026-08-13 batch (`ltidisafe` GCS dep-confusion dropper ring `check-audit`+`cspell-esm`+`eslint-publish-release`+`in-install`+`knip-bun`+`resolve-audit`+`napi-raw`, `31.97.137.157:45000` bare-IP Chromium-DPAPI stealer kit `vexium-kit`+`ventra-kit`+`velora-kit`+`vortex-kit`+`copytrade-core`+`prediction-trader`, `@hzero-front-ui/*` internal-scope dep-confusion 5-package cluster with `callback.m0chan.co.uk` DNS+HTTPS beacon, `@khaznatech/*` webhook.site preinstall exfil 3-pack, `jchunt.top` telemetry-canary series `wct-st`+`tizen-webdriver-cli`, `8.135.48.40:4444` reverse-shell date-fmt masquerade pair `datefmt-util-helper`+`date-fmt-helper-xz`, `notafollower` AWS IMDSv2 credential theft, `bs58-15` base58 typosquat via `base65-15x` transitive, `@solana-js/web3` Windows PowerShell + `files.catbox.moe` RCE, `postcss-initialize-plugin` Ethereum-RPC-C2 continuation, `mutex-forge` Telegram+Slack+Ethereum-Sepolia RAT, `chai-as-reformed`+`process-live-log`+`external-process-live-log`+`minimalistic-assert-plus` Function-constructor R-shell family, `node-config-svg-contract` eval-from-URL, `nc-verify-127942`+`@jacksher/install-exec-poc` OAST recon POCs, `cilm-ui-commons` pipedream.net preinstall, ~10 boilerplate CWE-506)
- GitHub Advisory npm CWE-506 sweep - 2026-08-12 batch (Web3 typosquat webhook.site ring day-2 `permit2`+`camelot-ammv2-*`+`boring-vault`+`augustdigital-sdk`+`upshift-*`, Ethereum-RPC-C2 `envpack-conf`+`tailwind-form-templates` XOR-encrypted second-stage on blockchain, `svelte-kit-vim`+`kit-map-vim` map-streak-kit day-4 continuation, `sui-gql`+`bcs-compact` Sui `@mysten/*` typosquat continuation, ~50-package `@years17/18/19/20/*` n8n-nodes-utils-helper red-team SSH-backdoor mass drop, `internallib_v756`/`v392` bare `/dev/tcp/10.0.74.63/4444` reverse shell, `mcp-util-helpers` webhook.site R-shell channel, `passkeys-react` Burp Collaborator OAST recon, `bb-twl-k7x2` Twilio-internal dep-confusion, `@telekom-ods/react-ui-kit` Deutsche Telekom internal-scope, `verify-cli`+`@assetshop/verify-cli` OAST recon pair, `dakumangalsingh` Java-Robot RAT with jpackage wrapper, boilerplate CWE-506 mass npm flood ~100 packages)
- GitHub Advisory npm CWE-506 sweep - 2026-08-11 batch (webhook.site Web3 typosquat credential-theft ring `@openzeppelin-4/5/contracts`+`@aerodrome-finance/contracts`+`@aerodrome-finance/slipstream`+`ethereum-vault-connector`, `safe-local-env-loader` env-local RAT sibling, `newtun` unencrypted-WebSocket PTY RAT with self-update, `svelte-vim-kit`+`kit-vim-map` map-streak-kit family continuation, `@nzeros/codebreak` Go ELF disguised as C solver, `base65-*` base-x typosquat cluster with 123KB obfuscated payload + `bs58-*` boilerplate siblings, coordinated `oastify.com`/`sslip.io`/webhook OAST dep-confusion recon beacons)
- GitHub Advisory npm CWE-506 sweep - 2026-08-10 batch (`iconova-react` + `postcss-initial-provider` on-chain Ethereum RPC dead-drop C2 loader pair, `svelte-kit-streak`+`kit-map-streak` Linux implant continuation of the map-streak-kit family, `@rblxts/services` catbox.moe Windows RAT sibling of last week's `@rbx-ts/services`, `@kuperka/chainguard-sdk` browser-form + wallet exfil, `xerohub-discord-voice` Discord-token stealer, `env-local` Windows persistent screen-capture + remote control, `hex-encode-utils` Cloudflare-Workers AES-GCM Python-payload loader, `cryptostock`/`tokocrytodev` Infura wallet-drainer, `simple-date-formatter-new-9/10` bash reverse shell to 124.221.154.135:4444, `polymarket-stake-mathss` log-taker.store loader, `chai-tracker` chai-spies impersonator with `dbconnectify` C2, `@noobaihome/amis-*-area-widget` Baidu-internal dep-confusion SSRF probe, and multi-vendor SQLite/postcss/commonjs/eth-library typosquat clusters)
yarn.lock security questions
- Does this work with Yarn Plug’n’Play?
- Yes. PnP changes how modules are resolved at runtime, not how the lockfile records versions. Your yarn.lock still lists resolved versions and we read it the same way.
- Does `yarn audit` do the same thing?
- Not quite.
yarn auditqueries an advisory database for known vulnerabilities in legitimate packages. Deliberately malicious packages get pulled from the registry quickly, and after that the advisory lookup often comes back clean even though the bad version is still pinned in your lockfile. We match against the malicious versions themselves, so takedown does not hide them. - Is my yarn.lock sent to a server?
- No. Parsing and matching happen in your browser. Nothing containing your lockfile leaves the machine.
Check another file
We only list package versions named by the original advisory - we don't infer compromises. Spotted one we're missing? Send it in.