The incidents behind a package’s reputation. Read what happened, which releases were affected, and what the original investigators found.
Reviewed reports · last reviewed 2026-09-05. This is a selected incident record, not an exhaustive live threat feed. A past compromise does not establish that the current release is compromised.
Wiz reported that hijacked releases added a malicious dependency that ran during compilation. Rust responders removed those releases. Wiz also identified infrastructure shared with previously reported DPRK-linked campaigns.
Checked every five minutes. Last completed check: 2026-09-05T20:58:24.610Z. Package mentions are automated leads, not confirmed vulnerability findings. Their checks refresh maintenance signals and do not prove an affected version is safe.
No matching feed articles recorded yet.
High-profile vulnerabilities and your dependencies
Astra’s top-ten article ↗ collects historical CVEs from 2020–2022. It is not a live ranking or the OWASP Top 10. The mapping below explains which entries relate to package identities we check.
An identity match is a reason to investigate, not confirmation that your installed release is vulnerable. Manifest checks do not establish runtime configuration or resolve every transitive dependency.
Requires Windows and domain configuration assessment.
Outside package-only scan coverage
Runtime vulnerabilities on OpenCVE
Browse CVEs by vendor and product. Runtime CVEs do not automatically apply to every package in that ecosystem; verify affected versions and configurations.
RSS sources are polled independently every five minutes. Clear tracked-package mentions trigger priority checks; they do not establish that an installed version is vulnerable. Sources without an RSS link and Feedspot’s directory are browsing resources. Reviewed reports above remain curated.