Local package security for developers

Find compromised packages across every local project.

Scan local projects for known malicious, compromised and vulnerable package versions. See the exact package, version, project and dependency path without uploading your source code.
No account required to scan
Source code stays on your machine
Package, project and path in one report
Open any finding to see the affected version, dependency path, source advisory and recommended action.
LOCAL PACKAGE SCAN
Runs on this device

Three steps to your first useful result

01
Choose your projects
Select one or more folders, with common locations suggested for you.
02
Run a private scan
Developer Defence reads supported manifests and lockfiles without uploading your source.
03
Work through the next batch
Project-first results put the most critical, actionable findings first.
Your first useful result appears before any account or payment request.
Private by default
Scans run on your machine.
Exact findings
Package, version, project and dependency path.
Practical guidance
Review source advisories and recommended next steps.
Pro and Guard roadmap
Safe Fix and credential protection follow the free scanner.
Published intelligence snapshot

Newly disclosed package risks.

Track malicious packages and high-impact vulnerabilities across the ecosystems you use. Each report includes affected versions, evidence and remediation.
Current snapshot
31 Aug 2026, 20:43 UTC
active package risks
252744
npm
Known malicious
Developer Defence priority
100/100 · Critical
@worrisome/reutil
MAL-2026-15604
Malicious code in @worrisome/reutil (npm)
Affected
0 → …
Updated
31 Aug 2026, 07:15 UTC
Open source advisory
PyPI
Vulnerable
Developer Defence priority
80/100 · Critical
restrictedpython
GHSA-ffg3-p8fm-mjx2
RestrictedPython guard hooks can be shadowed via positional-only arguments
Affected
0 → …; … → 8.3
Updated
31 Aug 2026, 04:40 UTC
Open source advisory
npm
Known malicious
Developer Defence priority
100/100 · Critical
@lucideproxy/svg
MAL-2026-15600
Malicious code in @lucideproxy/svg (npm)
Affected
0 → …
Updated
31 Aug 2026, 01:15 UTC
Open source advisory
npm
Known malicious
Developer Defence priority
100/100 · Critical
grafeno-actions
MAL-2026-15596
Malicious code in grafeno-actions (npm)
Affected
999.0.0
Updated
30 Aug 2026, 23:30 UTC
Open source advisory
How Developer Defence prioritises package risks
Check your projects against the current snapshot
Download Developer Defence and run a private local scan against the same signed intelligence.
Download now
Check your projects against the current snapshot
Download Developer Defence and run a private local scan against the same signed intelligence.
Download now
Technical report

From advisory to action.

The technical report puts affected versions, source advisories, observed behaviour and practical remediation in one clear view.
MAL-2026-15604
Malicious code in @worrisome/reutil (npm)
Package
npm / @worrisome/reutil
Affected versions
0 → …
Classification
Known malicious
Developer Defence priority
100/100 · Critical
First fixed version
Advisory updated
31 Aug 2026, 07:15 UTC
Recommended next step
Review the dependency path, then move to the first fixed version.
Open source advisory
Advisory excerpt
Published as part of a ClickFix-style fake-CAPTCHA phishing campaign documented by OX Security (see reference). The package's only file is index.html, declared as the npm "main" entry; package.json defines no preinstall/install/postinstall/prepare lifecycle script, so the payload does not execute at npm install time. index.html renders a fake Cloudflare Turnstile verification widget. An obfuscator.io-obfuscated…
Publication provenance
Generated mechanically from the latest complete, verified client intelligence publication.
Source release
keldra-index-1958
Snapshot digest
32d56468fb750da01456a2226e2773eecbfd81241e34b1d05c54a0e26d65105b
PersonalDB · TUF · SHA-256
Plans that grow with you

Scan free today. Add automation and protection when they are ready.

The complete local scanner is free. Paid automation, runtime protection and cloud-backed investigation extend value already demonstrated by the scanner.
01
Free · Scan
$0
Find known malicious, compromised and vulnerable package versions across local projects.
Project-first results and all matches
No account before the first result
Package, version, project and path
Manual remediation guidance
Download now
02
Pro · Fix · Planned
$10
/month
Repair findings safely without hand-editing every manifest and lockfile.
Branch, diff, build and test validation
Post-fix re-scan and rollback
Verified dependency upgrades
Scheduled and continuous scans
Billing arrives in v0.2.1
03
Guard · Protect · Planned
$20
/month
Add the encrypted vault and stop unauthorised processes reaching developer credentials.
Protected paths and approval prompts
Short-lived access grants
Process, package and parent-chain context
Install receipts and access replays
Planned after Pro
04
Complete · Respond · Planned
$30
/month
Preserve metadata evidence and understand what later-compromised software touched.
Retrospective exposure analysis
Rotation plans and evidence bundles
Cloud-backed access metadata
Multi-device history and alerts
Planned after Guard
Planned monthly pricing is shown in USD. The free scanner does not ask for payment or require an account.
Private by default

Your projects stay on your machine.

Developer Defence analyses package metadata locally and does not upload your scan results or source code.
01
On-device scanning
Project inventory and package matching run locally.
02
Signed intelligence updates
Only verified signed publications become active.
03
Public profiles · Planned
Future privacy-redacted sharing remains your choice.
04
Cloud investigation · Planned
Access metadata is planned; credential values are never stored.
Common questions

Straight answers before you download.

Common questions
Does a finding mean my machine was compromised?
No. A finding identifies a known affected version in scan scope. Whether it executed or caused impact requires additional evidence.
Common questions
Does the scanner include Safe Fix or the credential vault?
No. The local scanner is free. Safe Fix is planned for Pro and credential protection for Guard.
Common questions
Does AI classify packages as malicious?
No. Classifications and affected versions come from published advisory sources.
Common questions
Can the scanner publish a profile or redacted report?
No. Public profiles, badge exports and shareable receipts are roadmap previews. Current scan results remain local.
Common questions
What will a future green badge mean?
It will mean no known affected versions were found in the stated scope at the stated time—not a universal security certification.
Common questions
How current are package reports?
The backend serves the newest verified signed intelligence and keeps the last known-good generation when refresh fails.
Free local scanner

Download Developer Defence.

Choose the signed installer that matches your operating system and processor architecture.
Verify installer SHA-256 checksums
Windows
Windows
Jam Data Solutions-signed installers for 64-bit Windows 10 and Windows 11.
Windows x64
x86_64-pc-windows-msvc
Download .exe
Windows ARM64
aarch64-pc-windows-msvc
Download .exe
Microsoft Store · Coming soon
Store listing
Coming soon
Linux
Linux
Self-contained installers for supported 64-bit Linux systems.
Linux x86_64
x86_64-unknown-linux-gnu
Download .run
Linux ARM64
aarch64-unknown-linux-gnu
Download .run
macOS
macOS
Notarised installers for macOS 13 or later on Apple Silicon and Intel Macs.
Apple Silicon
aarch64-apple-darwin
Download .pkg
Intel Mac
x86_64-apple-darwin
Download .pkg
Apple App Store · Coming soon
Store listing
Coming soon