Latest incident:GitHub Advisory malware sweep - 2026-08-17 / 2026-08-18 batch (Sui blockchain `@mysten/*` typosquat days 4-5 continuation `sui-move-graphql`+`sui-move-rpc`+`sui-gql-core`+`bcs-core`+`bucket-protocol-sdk-v2`, Tinkoff BNPL dep-confusion tail `bnpl-blocks-independent-bnpl-search`, LEB128 encoding typosquat pair `leb128x`+`ulebkit`, generic CWE-506 boilerplate `blastradar`+`runtime-health`, PyPI `socks5901` Android `/sdcard/` Telegram-bot exfiltrator) (18 Aug 2026)

Check your project forcompromised dependencies

Paste your package-lock.json, pnpm-lock.yaml, yarn.lock, or requirements.txt. See in seconds whether you were exposed to one of 2026's supply-chain compromises.

Everything runs in your browser. Your lockfile never leaves your machine.

152 incidents3,609 packages tracked across all of them10 ecosystemsData range 15 Sept 2025 18 Aug 2026Last updated 18 Aug 2026

Parsed locally in your browser. Nothing leaves your device, no logging, no network round-trip.

Checking a specific file?

Each checker explains what it reads from that format and how confident the answer is.

Understanding the risk

DependencyWatch.io is one thing we do.Talk to us about the rest.

The same UK team that runs this feed runs CREST-accredited pen tests, a 24/7 SOC, and a live threat-intelligence practice. If you want the signal from this scanner feeding your defences directly, talk to us.

Talk to Precursor