Detect and block malicious packages in supply chain. Understand your dependencies, fix vulnerabilities in one click, and turn the evidence into enterprise-grade audit reports.
OpenHack combines software composition analysis with supply chain intelligence to find vulnerable dependencies and identify malicious dependencies. Map direct and transitive dependencies, connect findings to the repositories that use them, and block malicious packages in your supply chain workflow.
Go from findings to action with one-click fix pull requests. Package the results into enterprise-grade audit reports with an executive risk summary, a prioritized remediation plan, time-to-fix metrics, and the evidence behind each change.
From package intelligence to a reviewed fix
Package intelligenceExample
npm · Version 1.0.0@demo/build-utils
Malicious release
Threat intelligenceMalicious package match
Affected releasePackage and version matched
Repository contextweb-app / package-lock.json
Package decisionBlocked
Evidence attached
Automatically catch malicious packages with OpenHack Supply Chain Intelligence
A malicious package is more than an outdated dependency. OpenHack uses supply chain intelligence to identify and block malicious packages in npm and PyPI. Connect the package and affected version to your dependency inventory, so your team can see where the threat appears and act on the finding.
web-appYour repository
ui-kitDirect 3.2.0
shared-utilsTransitive 1.4.0
mail-clientDirect 2.1.0
address-parserTransitive 1.2.0
Direct and transitive dependenciesIllustrative packages
See the whole dependency tree
The packages you install are only the beginning. OpenHack maps direct and transitive dependencies from your manifests and lockfiles, so you can see the components underneath each application and how they connect. Bring that inventory together across your connected repositories.
Compare repositoriesExample
shared-utilsInstalled versions across your stack
Repository
1.4.01.6.2
web-appvia ui-kit
1.4.0
api-serviceDirect dependency
1.6.2
workervia ui-kit
1.4.0
Version drift detected2 versions · 3 repositories
Find the drift between repositories
The same package can look different across your stack. Compare installed versions across applications and services, spot where repositories have diverged, and identify components that need attention. See whether a package is used directly or arrives through another dependency before planning an update.
Update 2 dependenciesnpm + PyPI · Fix versions included
Ready for your review and compatibility checks
One click to a fix pull request
Turn fixable npm and PyPI findings into a pull request with one click. Select the affected packages and OpenHack prepares the dependency updates, keeping the vulnerabilities and target versions together. Your team reviews the changes, checks compatibility, and decides when to merge.
Dependency inventory
sbom.cdx.jsonPreview
Software bill of materialsCycloneDX 1.5
"specVersion":"1.5"
ComponentsNames, versions & package URLs
LicensesLicense information where available
DependenciesDirect & transitive relationships
Ready to shareJSON
Share your SBOM in CycloneDX 1.5
Generate a Software Bill of Materials (SBOM) from your dependency inventory and export it as CycloneDX 1.5 JSON. Bring package names, resolved versions, available license information, and dependency relationships into one shareable file. Give customers and security reviewers a clear inventory of your software, in a format compatible with tools that support CycloneDX 1.5.
Give security reviewers and enterprise buyers the full picture: an executive risk summary, prioritized remediation plan, dependency and license context, and a traceable remediation trail. Include time-to-fix metrics, including median time to fix, so the report shows both the remaining risk and your team's progress addressing it.
What you get
Supply chain intelligence for malicious npm and PyPI packages
Dependency inventories, affected versions, and repository context
One-click fix pull requests for supported dependency updates
CycloneDX 1.5 JSON SBOMs for sharing and security reviews
Enterprise audit reports with a prioritized remediation plan
Time-to-fix metrics and a traceable remediation trail
Put your AI security engineer to work.
Connect your repositories to detect malicious packages, fix vulnerable dependencies, and give your team the evidence to move enterprise security reviews forward.