+2.5M 24h
THREAT INTELLIGENCE
See threats Stop breaches.
PexLens continuously monitors enrolled devices and package activity in the background, running scheduled scans and checking device heartbeats to keep security analysis up to date.
Request a DemoGuardDog Findings
0.3M
IOC IPs
0.0K
IOC Domains
0.3M
IOC Emails
0.7K
Bitcoin Addresses
0.7K
YARA Rules
0
Live statistics from the PexLens threat intelligence pipeline.

WHAT WE MONITOR
Comprehensive visibility across the threat landscape
PexLens collects, correlates, and analyzes high-fidelity signals from across the software ecosystem and the wider internet.
Explore our coverageMalicious Packages
Detect and track malicious packages across all major ecosystems.
Malware & Tooling
Monitor malware families, tooling, and attack frameworks.
Infrastructure
Track domains, IPs, URLs, and hosting infrastructure.
Vulnerabilities
Continuously ingest CVEs and OSV advisories.
Attacker Behavior
Analyze TTPs, campaigns, and emerging threats.
Community Signals
Leverage reports from security researchers and users.
THREAT INTELLIGENCE FEED
Recent intelligence updates
RESEARCH FROM THE PEXLENS PIPELINE
Research, findings & threat analysis
Security research collected, analyzed, and tracked across the software ecosystem — from vulnerabilities and malicious packages to emerging attacker techniques.
TOP THREAT ECOSYSTEMS
Where threats are emerging
Threat detections across package ecosystems over the last 90 days.
- npm
- PyPI
- Maven
- NuGet
- RubyGems
About this data
Detections are aggregated from our threat intelligence pipeline, including scanners, crawlers, community reports, and OSINT sources.
View detailed breakdownGET THREAT INTELLIGENCE YOUR WAY
Integrate. Automate. Stay ahead.
Access PexLens threat intelligence via our APIs, feeds, and integrations.
API Access
Real-time threat intelligence via RESTful APIs.
OSV Feed
Consume data in the Open Source Vulnerability format.
Webhooks
Get instant alerts for new threat detections.
Stay Ahead of Supply Chain Threats
Turn intelligence into action.
See the full risk profile behind every package — before it enters your codebase.
