See It for Yourself.

Pick two versions of a real npm package. Vigilance compares them and flags any file that gained a capability the old version did not have. It reads the files. It never runs the package.

Type any npm package to compare two of its versions.

demo-utils 1.0.0 → 1.1.0
loading…

Vigilance reads files. It never runs the sample. Each replay is a faithful reconstruction of the attack, because the real malicious releases are not redistributed. Every payload file is inert. A live diff has a size cap and a rate limit. Very large packages do not run here.