Sandbox detonation is deliberately narrow. It is the most expensive analysis layer and is applied where earlier analysis identifies signals that warrant deeper investigation.
PEXLENS RESEARCH · REPORTS
Research Reports on the Software Supply Chain
Long-form analysis of software supply-chain threats, attack patterns, package ecosystems and the security controls organizations need to stay ahead.

RESEARCH PIPELINE
The scale behind the research
PexLens continuously tracks package versions and analyses software artifacts across the PyPI and npm ecosystems, giving our researchers a live view of the software supply chain.
0.3M
ARTEFACTS PULLED & INSPECTED
63.6% of all versions
0.7M
ARTEFACTS PULLED & INSPECTED
63.6% of all versions
0.5M
VERSIONS MATCHED
Against known-vulnerability data
0.1M
VERSIONS DETONATED
In the behavioural sandbox
Source: PexLens package pipeline, PyPI and npm, rolling 24-hour snapshot.

FEATURED REPORT • 2026
The State of the Software Supply Chain
A year of registry telemetry, attack-pattern analysis and what changed in how open-source software is compromised.
01
Malicious publishing is changing
How malicious publish volume moved quarter by quarter.
02
Malicious publishing is changing
How malicious publish volume moved quarter by quarter.
03
Malicious publishing is changing
How malicious publish volume moved quarter by quarter.
Get the 2026 Report
Includes key findings, data, and practical recommendations.
By submitting, you agree to our Privacy Policy and Terms of Service.
Exclusive data & analysis
Registry telemetry and research you won't find anywhere else.
Actionable insights
Clear takeaways for security, engineering and leadership.
Threat trends & patterns
Understand what changed, who's behind it and why.
Practical recommendations
Real-world guidance to reduce risk across your supply chain.
RESEARCH LIBRARY
Explore our research
Deep dives, benchmarks and annual analysis from the PexLens security research team.
ANNUAL REPORT · 2026
The State of the Software Supply Chain
A year of registry telemetry, attack-pattern analysis and what changed in how open-source software is compromised.
2026 · ANNUAL REPORT
Read ReportRESEARCH REPORT
Software Supply Chain Threat Landscape
A data-driven view of the threats emerging across modern package ecosystems and the attack patterns behind them.
2026 · ANNUAL REPORT
Read ReportBENCHMARK
AI-generated Code: A Security Benchmark
What assistants get wrong, measured across 10k samples.
2026 · ANNUAL REPORT
Read ReportRESEARCH REPORT
State of Open Source Security
Long-form analysis of software supply-chain risk, malicious packages and the changing security landscape.
2026 · ANNUAL REPORT
Read ReportHOW WE ANALYSE
Every version, through six layers of analysis
PexLens starts with the full package-version universe and progressively applies deeper analysis where the signals justify it.
INDEXED
0.3M
(100%)
All package versions across PyPI and npm
ARTEFACT PULLED
0.7M
(63.6%)
Package artefacts successfully pulled
KNOWN-VULN MATCH
0.5M
(15.3%)
Versions matched against known-vulnerability data
STATIC ANALYSIS
0.5M
(22.2%)
Static code and manifest analysis
HEURISTIC SCAN
0.6M
(20.6%)
Heuristic rules for suspicious behaviour
SANDBOX DETONATION
0.1M
(2.2%)
Behavioural sandbox detonation
RESEARCH BY THE NUMBERS
The software supply chain keeps expanding
More package releases mean more change entering development environments—and more opportunities for malicious or vulnerable components to reach software at scale.
Annual releases have more than doubled since 2021 — from 6.0M to 13.7M.
Package Version Releases (Millions)
| Year | Releases | YoY |
|---|---|---|
| 2021 | 6.0M | — |
| 2022 | 7.3M | +23% |
| 2023 | 9.1M | +25% |
| 2024 | 10.6M | +15% |
| 2025 | 11.4M | +8% |
| 2026 | 13.7M | +20% |
Source: PexLens package pipeline. Pre-2021 backfilled timestamps are excluded from year-over-year comparison.
RESEARCH METHODOLOGY
From signal to published finding
01
Detect
Behavioural analysis across every public registry surfaces anomalous publishes within minutes.
02
Verify
Researchers detonate the sample in an isolated sandbox and confirm intent by hand. No finding ships on a heuristic alone.
03
Disclose
Maintainers and registry operators are notified first, with a 90-day coordinated window before public write-up.
04
Protect
Every confirmed finding becomes a detection rule in the PexLens platform on the same day.
RESEARCH AND PROTECTION
Everything our researchers find becomes protection you already have.
Findings on this page ship as detections in the PexLens platform the day they are confirmed.
