Your RSA-2048 keys break in 2030. Find every one of them before attackers do.

Malicious package campaigns

Most malicious packages don't arrive alone. A single compromised publisher scope or coordinated campaign often floods a registry with hundreds of near-identical packages at once, each impersonating a real dependency. These are the clusters — grouped so you can check a whole campaign against your lockfiles instead of one package at a time.

Tracked campaigns
196
Malicious packages
13,289
npm campaigns
154
Largest campaign
4,544

Campaigns first detected, by year

Coordinated package flooding is a recent pattern — and accelerating.

Packages published per campaign

Most campaigns are modest; a handful flood registries with hundreds or thousands.

All tracked campaigns

Ranked by package count. Each campaign page carries the full roster and the response steps for that cluster.

Campaign / scopePackages