Latest incident:GitHub Advisory malware sweep - 2026-09-24 (late) + 2026-09-25 (npm `@nf-addons/am-global-header` + `@osl-design/react` `oob.algamil7x.xyz` DNS-OOB day-7 late-adds missed by yesterday`s sweep; `n8n-nodes-moonlet-helpers`/`-utils`/`n8n-nodes-flowstats` `mkicom.com` fake `.well-known/pki-validation/` dropper family with `104.21.3.16` bare-IP + magic-key RCE; `secure-env3` + `better-dotenv3` JPEG-APP13/APP14 hidden VBS/PowerShell Windows dotenv typosquat dropper family; `agency-test-exercise` + `agency-testts` `wscript.exe 4444.vbs` AES+ChaCha20 Windows dropper; `chromatitle` + `chromatitle-js` ANSI-color-lure obfuscated fetch-and-execute; `wallet-connect-adapter` Windows XOR-encrypted Python dropper; `simple-date-formatter-new-11/13/14/15` continuation of the `124.221.154.135` SSH-key + `oast.fun` campaign (13/14/15 new C2 hosts); `aliftech-ui` + `@birbalo/aliftech-ui` shared-`webhook.site` dep-confusion siblings; `@alphaspace/core` Yahoo-internal dep-confusion Pipedream + istio/yahoo DNS recon; `eslint-config-compact-base` AWS API Gateway CI recon; `c2-client` postinstall command channel; pip `prosocks` proxy-network hijack campaign + `my-private-pkg` + `vercel-runtime-python` Vercel dep-confusion pentests) (25 Sept 2026)

Check your project forcompromised dependencies

Paste your package-lock.json, pnpm-lock.yaml, yarn.lock, or requirements.txt. See in seconds whether you were exposed to one of 2026's supply-chain compromises.

Everything runs in your browser. Your lockfile never leaves your machine.

193 incidents4,887 packages tracked across all of them10 ecosystemsData range 15 Sept 2025 → 25 Sept 2026Last updated 25 Sept 2026

Parsed locally in your browser. Nothing leaves your device, no logging, no network round-trip.

Checking a specific file?

Each checker explains what it reads from that format and how confident the answer is.

Understanding the risk

DependencyWatch.io is one thing we do.Talk to us about the rest.

The same UK team that runs this feed runs CREST-accredited pen tests, a 24/7 SOC, and a live threat-intelligence practice. If you want the signal from this scanner feeding your defences directly, talk to us.

Talk to Precursor