ACME Corp · supply-chain dashboard

Generated 2026-05-05 02:26 UTC · static report · no telemetry
5
Scans
15
Packages scanned
4
Compromised
0
HIGH/CRITICAL CVEs
1
Ecosystems
0
Parse errors

Scan sources

SourceToolLockfilesPackagesMALHIGH/CRIT
/tmp/pd-scans/repo-cap.json0.1.01120
/tmp/pd-scans/repo-java-svc.json0.1.01300
/tmp/pd-scans/repo-legacy-node.json0.1.01220
/tmp/pd-scans/repo-ml-pipeline.json0.1.01800
/tmp/pd-scans/repo-website.json0.1.01100

Campaign rollup

AdvisoryKindCampaignEcosystemsHitsSources
EXTRA-2018-0001MALICIOUSevent-stream / flatmap-stream credential stealernpm21
EXTRA-2026-0001MALICIOUSMini Shai-Hulud (SAP CAP)npm11
MAL-2026-3178MALICIOUSnpm11

All findings

Severity:
Ecosystem:
KindPackageAdvisoryCampaignLockfileSource
MALICIOUSnpm:@cap-js/sqlite@2.2.2EXTRA-2026-0001 [ref] [ref] [ref]Mini Shai-Hulud (SAP CAP)tests/fixtures/npm/mini-shaihulud.lock.json/tmp/pd-scans/repo-cap.json
MALICIOUSnpm:@cap-js/sqlite@2.2.2MAL-2026-3178 [ref] [ref]tests/fixtures/npm/mini-shaihulud.lock.json/tmp/pd-scans/repo-cap.json
MALICIOUSnpm:event-stream@3.3.6EXTRA-2018-0001 [ref] [ref] [ref]event-stream / flatmap-stream credential stealertests/fixtures/npm/historic-event-stream.lock.json/tmp/pd-scans/repo-legacy-node.json
MALICIOUSnpm:flatmap-stream@0.1.1EXTRA-2018-0001 [ref] [ref] [ref]event-stream / flatmap-stream credential stealertests/fixtures/npm/historic-event-stream.lock.json/tmp/pd-scans/repo-legacy-node.json