+2.5M 24h
THREAT INTELLIGENCE
See threats Stop breaches.
PexLens continuously monitors enrolled devices and package activity in the background, running scheduled scans and checking device heartbeats to keep security analysis up to date.
Request a Demosandbox scanning stats
0.3M
IOC IPs
0.0K
IOC Domains
0.3M
IOC Emails
0.7K
Bitcoin Addresses
0.7K
Static scanning stats
0
Live statistics from the PexLens threat intelligence pipeline.

WHAT WE MONITOR
Comprehensive visibility across the threat landscape
PexLens collects, correlates, and analyzes high-fidelity signals from across the software ecosystem and the wider internet.
Explore our coverageMalicious Packages
Detect and track malicious packages across all major ecosystems.
Malware & Tooling
Monitor malware families, tooling, and attack frameworks.
Infrastructure
Track domains, IPs, URLs, and hosting infrastructure.
Vulnerabilities
Continuously ingest CVEs and OSV advisories.
Attacker Behavior
Analyze TTPs, campaigns, and emerging threats.
Community Signals
Leverage reports from security researchers and users.
THREAT INTELLIGENCE FEED
Recent intelligence updates
RESEARCH FROM THE PEXLENS PIPELINE
Research, findings & threat analysis
Security research collected, analyzed, and tracked across the software ecosystem — from vulnerabilities and malicious packages to emerging attacker techniques.
MALWARE / THREAT ANALYSIS
Shai-Hulud "Trinitite" Malware Hits @7nohe npm Package
Analysis of malicious package activity and emerging supply-chain threats.
CRITICAL
VULNERABILITY RESEARCH
Vulnerability Management Tools: Detect & Remediate Software Risk
Overview of key vulnerability management approaches and remediation strategies.
ANALYZED
THREAT INTELLIGENCE
AWS S3 Bucket Security: What Secret Scanning Adds
How secret scanning helps uncover exposed credentials and reduce cloud risk.
PENDING
AI / APPLICATION SECURITY
AI Agent Threat Response: Why Runtime Detection Isn't Enough
Exploring the limitations of runtime detection and how to build stronger threat response.
PENDING
TOP THREAT ECOSYSTEMS
Where threats are emerging
Threat detections across package ecosystems over the last 90 days.
- npm
- PyPI
- Maven
- NuGet
- RubyGems
About this data
Detections are aggregated from our threat intelligence pipeline, including scanners, crawlers, community reports, and OSINT sources.
View detailed breakdownGET THREAT INTELLIGENCE YOUR WAY
Integrate. Automate. Stay ahead.
Access PexLens threat intelligence via our APIs, feeds, and integrations.
API Access
Real-time threat intelligence via RESTful APIs.
OSV Feed
Consume data in the Open Source Vulnerability format.
Webhooks
Get instant alerts for new threat detections.
Stay Ahead of Supply Chain Threats
Turn intelligence into action.
See the full risk profile behind every package — before it enters your codebase.
