SECURITY ADVISORIES
Affected versions. All versions. Dates.
The PexLens research team publishes as a formal advisory. Each advisory includes a permanent ID you can cite in a ticket, an audit report, or an email.
0
advisories published
0
rated critical
0
CVE IDs credited
0h
median publish time

03 Severity Explained
What each level asks you to do
Severity is Editorial
A researcher may raise or lower the CVSS-derived level based on real-world exploitability. When they do, the advisory shows both the computed score and the reason for the override.
Critical
CVSS 9.0 – 10.0
Act today
Active exploitation or a malicious package in wide use. Assume compromise and rotate credentials.
High
CVSS 7.0 – 8.9
Act this week
Serious impact but conditions apply — specific configuration, version or reachable code path.
Medium
CVSS 4.0 – 6.9
Next planned release
Real but limited impact, or hard to reach in a typical deployment.
Low
CVSS 0.1 – 3.9
Note it
Worth recording for completeness. No urgency, but the register stays honest by including it.
03 ADVISORY SEVERITY
We score severity using industry standards.
Every advisory is evaluated using CVSS v3.1 to help you prioritize risk and focus on what matters most.
CVSS v3.1
Common Vulnerability Scoring System
Critical
CVSS 9.0 – 10.0
Active exploitation or a malicious package in wide use. Assume compromise and rotate credentials.
High
CVSS 7.0 – 8.9
Serious impact but conditions apply — specific configuration, version or reachable code path.
Medium
CVSS 4.0 – 6.9
Real but limited impact, or hard to reach in a typical deployment.
Low
CVSS 0.1 – 3.9
Worth recording for completeness. No urgency, but the register stays honest by including it.
ADVISORY CLASSES
Two types of findings we publish.
Malicious Packages
Intentional
Packages with intentional malicious behavior.
- May steal credentials, tokens, crypto or sensitive data
- Often part of campaigns or supply-chain attacks
- Indicators of compromise (IOCs) are provided
Vulnerabilities
Unintentional
Unintentional security weaknesses in otherwise legitimate packages.
- Bugs or design flaws that can be exploited
- Impact depends on configuration and usage
- CVE ID assigned when eligible
Sandbox & Runtime Analysis
Deep insights into suspicious behavior.
We execute packages in isolated environments to analyze runtime behavior and detect malicious and risky activity across all packages.

Total Scans
0
Malicious / Elevated Detections
0
Mitre Att&ck Techniques
0
Monitored Files
0
Processes & DNS
0
Threat Intelligence
Threat signals from across the ecosystem.
We collect and analyze threat indicators from multiple sources across the ecosystem and the open web.
IOC IP Addresses
0.0K
IOC Domains
0.3M
IOC Emails
0.7K
Bitcoin Addresses
0.7K
Socket Alerts
0.0K

Stay Ahead of Supply Chain Threats
Get early access to advisories and research.
Request a demo to see how PexLens helps you identify, prioritize and respond faster.
