
Package-Inferno
A Public Package Scanner for The Community

A Public Package Scanner for The Community

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

CVE-2026-33634 (CVSS 9.4) — The most impactful CI/CD supply chain attack of 2026 so far.

Research of CVE-2024-3094 vulnerability.

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Rogue Binary Model Context Protocol (MCP): a Docker-packaged binary analysis lab for AI agents. It supports reverse engineering, malware triage, and…

Real-time geospatial OSINT platform aggregating 60+ public telemetry feeds (ADS-B, AIS, satellites, CCTV) into a unified map with server-side recon…


😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

Protect against malicious code installed via npm, yarn, pnpm, npx, pnpx, pip, uv and poetry with Aikido Safe Chain. Free to use, no tokens required.

Proof of concept code for Datadog Security Labs referenced exploits.

FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.