Autonomous “Shai-Hulud” engine that ingests malicious NPM package advisories from OSV, tracks versions and metadata, and maintains a continuously updated threat intelligence database.
-
Updated
Jan 2, 2026 - JavaScript
Autonomous “Shai-Hulud” engine that ingests malicious NPM package advisories from OSV, tracks versions and metadata, and maintains a continuously updated threat intelligence database.
A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
Add a description, image, and links to the malicious-packages-db topic page so that developers can more easily learn about it.
To associate your repository with the malicious-packages-db topic, visit your repo's landing page and select "manage topics."