Opens in a new tab
Pricing

THREAT INTELLIGENCE

See threats Stop breaches.

PexLens continuously monitors enrolled devices and package activity in the background, running scheduled scans and checking device heartbeats to keep security analysis up to date.
Request a Demo
sandbox scanning stats
0.3M

+2.5M 24h

IOC IPs
0.0K

+8.7K 24h

IOC Domains
0.3M

+362.1K 24h

IOC Emails
0.7K

+12.2K 24h

Bitcoin Addresses
0.7K

+3.1K 24h

Static scanning stats
0

+7 24h

Live statistics from the PexLens threat intelligence pipeline.
WHAT WE MONITOR

Comprehensive visibility across the threat landscape

PexLens collects, correlates, and analyzes high-fidelity signals from across the software ecosystem and the wider internet.
Explore our coverage

Malicious Packages

Detect and track malicious packages across all major ecosystems.

Malware & Tooling

Monitor malware families, tooling, and attack frameworks.

Infrastructure

Track domains, IPs, URLs, and hosting infrastructure.

Vulnerabilities

Continuously ingest CVEs and OSV advisories.

Attacker Behavior

Analyze TTPs, campaigns, and emerging threats.

Community Signals

Leverage reports from security researchers and users.
THREAT INTELLIGENCE FEED

Recent intelligence updates

Explore our coverage
RESEARCH FROM THE PEXLENS PIPELINE

Research, findings & threat analysis

Security research collected, analyzed, and tracked across the software ecosystem — from vulnerabilities and malicious packages to emerging attacker techniques.
Explore our coverage

MALWARE / THREAT ANALYSIS

Shai-Hulud "Trinitite" Malware Hits @7nohe npm Package

Analysis of malicious package activity and emerging supply-chain threats.
CRITICAL

VULNERABILITY RESEARCH

Vulnerability Management Tools: Detect & Remediate Software Risk

Overview of key vulnerability management approaches and remediation strategies.
ANALYZED

THREAT INTELLIGENCE

AWS S3 Bucket Security: What Secret Scanning Adds

How secret scanning helps uncover exposed credentials and reduce cloud risk.
PENDING

AI / APPLICATION SECURITY

AI Agent Threat Response: Why Runtime Detection Isn't Enough

Exploring the limitations of runtime detection and how to build stronger threat response.
PENDING
TOP THREAT ECOSYSTEMS

Where threats are emerging

Threat detections across package ecosystems over the last 90 days.
  • npm2.8M 50.9%
  • PyPI1.6M 29.1%
  • Maven588K 10.7%
  • NuGet412K 7.5%
  • RubyGems112K 2.0%

About this data

Detections are aggregated from our threat intelligence pipeline, including scanners, crawlers, community reports, and OSINT sources.
View detailed breakdown
GET THREAT INTELLIGENCE YOUR WAY

Integrate. Automate. Stay ahead.

Access PexLens threat intelligence via our APIs, feeds, and integrations.
API Access
Real-time threat intelligence via RESTful APIs.
OSV Feed
Consume data in the Open Source Vulnerability format.
Webhooks
Get instant alerts for new threat detections.
Stay Ahead of Supply Chain Threats

Turn intelligence into action.

See the full risk profile behind every package — before it enters your codebase.