
NPM Sec Analysis
Recently, security incidents related to NPM poisoning attacks have been emerging one after another. When such incidents occur, the affected NPM packages are often removed or unpublished from the NPM registry, making subsequent security analysis difficult.
Based on this situation, a project has been created to collect and archive malicious NPM packages involved in poisoning attacks, serving as a resource for future security research and analysis.
Security researchers are welcome to submit Pull Requests and contribute to the project