Back to Home
Pre-Disclosure Detection of npm Hijacks

Supply Chain Attack Protection

Most SCA scanners tell you about supply-chain attacks AFTER the security community publishes an advisory — typically 6-72 hours after the attacker has already shipped malicious code. Sectora watches the npm registry directly for the leading indicators (maintainer changes, release bursts, version skips) and alerts on the live attack, not the post-mortem.

Start Free Trial

Key Capabilities

Comprehensive security testing designed for modern applications

Maintainer Hijack Detection

Every six hours we diff the npm-registry maintainer list for every package in your dependency tree against the prior baseline. New maintainer added → critical alert. Maintainer removed → high alert. Account hijack is the #1 supply-chain attack vector (chalk, ua-parser-js, eslint-config-prettier, event-stream — all involved a maintainer change moments before the malicious release).

Release-Activity Spike Detection

Popular npm packages release <1 version per month on average. A burst of 5+ releases in 7 days from a previously-quiet package is the canonical hijack signature — attackers push multiple malicious versions to maximize spread before legitimate owners notice. We flag the burst as soon as it happens.

Suspicious Version Bumps

Major-version skips (e.g. v5 → v7) bypass lockfile pinning and dependabot caution. We surface these alongside the activity-spike signal so you can tell apart a legitimate coordinated rewrite from a hijacker trying to slip past your CI's range constraints.

Package Unpublish Watch

When the npm registry 404s a package you depend on, we alert immediately. Unpublishing is rare and often signals either (a) a maintainer noticing a compromise and yanking, or (b) the compromise itself (left-pad-style supply disruption).

Code-Level Malware Analysis (Pro+)

When a new version is published on a package you depend on, we fetch the tarball and run code-level AI analysis on what was actually published — install scripts, entry points, native binaries — for malware patterns. Catches Tanstack-style hijacks where a compromised existing maintainer publishes malicious code without changing the metadata. The heuristic detectors above would miss this; only code-level analysis catches it. Requires Pro tier or higher.

Customer-Prioritised Watch List

We monitor exactly the packages your customers actually depend on (top-N by usage from your SCA scans), not the entire npm registry. Every signal is by-definition relevant to your customer base.

Critical Severity → Instant Email

Critical signals (maintainer added, package unpublished) trigger an immediate admin email with the full evidence diff, the affected package + version, and one-click links to the dashboard. High/medium signals appear on the dashboard chip but don't email, so you don't get alert fatigue.

Why Choose Sectora?

Built by security professionals for security professionals. Our platform combines speed, accuracy, and ease of use to help you find vulnerabilities before attackers do.

Get Started

Pre-disclosure detection — close the 6-72 hour window between attacker publishing and advisory filing

No code change to your apps — we watch npm directly, you keep your existing dependency manager

Deduped alerts — the same signal won't fire twice in 14 days, so one incident → one email, not 24

Full evidence trail — every signal includes the raw before/after npm metadata for your security team to audit

Acknowledge or false-positive any signal directly from the dashboard — your team's verdict trains the system

Zero false-negative bias — we err toward flagging suspicious activity; you can suppress with one click

Ready to Secure Your Applications?

Join security teams using Sectora to find and fix vulnerabilities faster.

Start Free Trial