0 / 0 packages
0 / 0 projects hit
Package (clean) Project / application Compromised Detected by SBOM scan
⚠ Couldn't load the 3D engineThree.js failed to load from the CDN. Check your connection and reload.

Software Supply Chain Compromise Propagation

Real software is built from a deep, nested tree of shared dependencies. This simulator lets you inject a malicious compromise into a single package inside a small dependency ecosystem and watch it silently climb the dependency graph — package by package — until it reaches every downstream application that transitively relies on it, while unrelated projects stay untouched. Compare the blast radius of compromising a deeply-embedded leaf package against an isolated one, then see how a Software Bill of Materials (SBOM) scan can detect the compromise across the whole graph almost instantly once its signature is known — in contrast to how long it can otherwise stay silent.