See It for Yourself.
Pick two versions of a real npm package. Vigilance compares them and flags any file that gained a capability the old version did not have. It reads the files. It never runs the package.
Type any npm package to compare two of its versions.
loading…
Vigilance reads files. It never runs the sample. Each replay is a faithful reconstruction of the attack, because the real malicious releases are not redistributed. Every payload file is inert. A live diff has a size cap and a rate limit. Very large packages do not run here.