Splunk Threat Research Team

PackageInferno Threat Explorer

Search, inspect, and triage risky npm packages surfaced by the PackageInferno pipeline. Explore install-chain risks, credential theft, and command-and-control patterns across thousands of analyzed packages.

Pipeline at a glance

Packages analyzed

—

Tracking — total packages

Past hour activity

0

Packages analyzed in the last 60 minutes.

Findings logged

—

High — • Medium — • Low —

Fresh telemetry

—

Last finding arrival

Jump In

Start with a search or browse high-risk packages by severity and rule category.

Bring your own package

Drop an npm package name or npmjs.com URL. If it's new, we'll queue it for analysis right away.

Supports npm package names and https://www.npmjs.com/package URLs only.

What's Inside?

  • • Install chain attacks that execute during npm install
  • • Credential harvesting, token exfiltration, and secrets scraping
  • • C2 beacons (Discord, Telegram), obfuscation, persistence tricks
  • • Package scores and severity rollups with per-rule context