DepWall

Home / Research

Research

Measured reports on npm supply-chain attacks and install-time detection — including what our own engine misses. Data and method published with each.

Two rules govern everything published here. Every figure is computed from data in this repository — the generator refuses to render a report containing a number it cannot derive. And the misses are published with the hits: a detection rate measured only against fixtures we wrote ourselves would report on our test suite, not on your risk.