BleedWatch
00 // INTEL / PACKAGES

Package metadata across NPM, PyPI, Docker.

Search package metadata, suspicious publish behavior, typosquat candidates, and dependency-confusion signals before they become customer-specific findings.

PACKAGE INDEX

Representative records

12 visible packages
EcosystemPackage nameVersionStatusFirst seenLast verified
npm@bleedwatch/scanner-cli3.7.1Clean 2026-04-122026-05-07
npm@bleedwotch/scanner-cli1.0.2Typosquat 2026-04-302026-05-07
npm@internal-package/api-client0.1.4Dep-confusion 2026-04-262026-05-06
pypifastapi-authz0.9.4Clean 2026-03-212026-05-07
pypireqeusts-oauth2.31.8Typosquat 2026-04-192026-05-07
pypicloud-token-tools4.2.0Malicious 2026-05-022026-05-07
dockerghcr.io/bleedwatch/apiprod-2026-05-01Clean 2026-04-012026-05-07
dockerdocker.io/bleedwatch-prod/apilatestDep-confusion 2026-04-292026-05-07
dockerregistry.example.com/frontendcanary-91Typosquat 2026-04-242026-05-06
npmlinear-webhook-tools0.6.5Clean 2026-03-092026-05-07
pypistripe-events-lite1.4.1Clean 2026-02-282026-05-05
dockerghcr.io/acme/workersha-9f42c1Malicious 2026-05-042026-05-07
02 // FLAGGING

How packages are flagged.

Public records are promoted only after multiple signals line up or a verified report confirms the suspicious package behavior.

Evidence weighted
01

Pattern matching

Registry names, README language, install scripts, and source URLs are compared against known impersonation and abuse patterns observed across public advisories.

02

Dependency-confusion heuristic

Public package names are scored when they resemble internal namespace conventions, private registry paths, or build metadata that should not resolve from the public internet.

03

Maintainer anomaly

New maintainers, abandoned projects, sudden publish bursts, and mismatched repository ownership are treated as risk signals until verified against known-good metadata.

04

Community reports

Researcher submissions and customer reports are normalized into the same evidence model, then deduplicated before a package is promoted into the public index.

SEARCH

Looking for a specific package?

Search public advisories, package records, hashes, and supply-chain patterns from one intel surface.

Open intel search