npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@profullstack/threatcrush

v0.13.12

Published

All-in-one security agent daemon — monitor, detect, scan, and protect servers in real-time

Readme


ThreatCrush is a security daemon that runs on your server, reading your logs and watching inbound connections for live attacks. It checks every nginx request against 96 OWASP CRS rules (paranoia level 1) + 1 ThreatCrush rule with CRS anomaly scoring, runs 15 detection rules over auth, web and network events, auto-bans attackers, scans your codebase, spot-checks your URLs, and alerts you in real-time.

$ threatcrush monitor

2026-09-25 12:03:41 [INFO]    Starting foreground monitor...
2026-09-25 12:03:41 [INFO]    Monitoring 3 log source(s):
  ● ssh-guard      → /var/log/auth.log
  ● log-watcher    → /var/log/nginx/access.log
  ● log-watcher    → /var/log/syslog

  Press Ctrl+C to stop

2026-09-25 12:03:45 [CRITICAL] [log-watcher]  Attack detected [SQLI]: GET /api/users?id=1%20UNION%20SELECT%20password%20FROM%20users (185.43.21.8)
2026-09-25 12:03:46 [CRITICAL] [log-watcher]  Attack detected [PATH_TRAVERSAL]: GET /../../etc/passwd (185.43.21.8)
2026-09-25 12:03:47 [HIGH]     [ssh-guard]    Failed SSH login for root from 91.232.105.3 (91.232.105.3)
2026-09-25 12:03:48 [HIGH]     [ssh-guard]    Invalid SSH user attempt: admin123 from 103.77.88.99 (103.77.88.99)
2026-09-25 12:03:52 [LOW]      [log-watcher]  Client error 404: GET /wp-login.php (203.0.113.9)

monitor tails your logs in the foreground. The daemon (threatcrush start) adds the connection poller, DNS monitor, journald, the rule engine and auto-ban.

Install

Preferred install:

curl -fsSL https://threatcrush.com/install.sh | sh

The CLI needs Node.js 22.6 or newer. The installer detects whether the machine is a server or desktop, uses your existing package manager when available, and on a machine with no Node.js sets up Node.js LTS with mise, adding mise's shims to ~/.profile so new login shells find threatcrush. If it finds an older Node.js it stops without installing anything and tells you how to upgrade.

  • Linux server → installs the CLI
  • Desktop (Linux, macOS, Windows) → installs the CLI and points you to the desktop app, a separate download from GitHub Releases. The desktop app talks to a ThreatCrush daemon on the same machine; log monitoring and firewall bans need Linux.

After install, the supported lifecycle commands are:

threatcrush update   # upgrades the installed bundle
threatcrush remove   # removes the installed bundle

Manual package-manager installs still work (Node.js 22.6+):

npm i -g @profullstack/threatcrush
pnpm add -g @profullstack/threatcrush
yarn global add @profullstack/threatcrush
bun add -g @profullstack/threatcrush

Usage

threatcrush              # Get started
threatcrush monitor      # Watch nginx, auth & syslog for attacks (foreground)
threatcrush tui          # Interactive dashboard (htop for security)
threatcrush scan ./src   # Scan code for vulnerabilities & secrets
threatcrush scan . --format sarif --output out.sarif --fail-on critical,high
threatcrush pentest URL  # Quick web security checks against a URL
threatcrush init         # Auto-detect services, generate config
threatcrush status       # Show daemon status & loaded modules
threatcrush modules      # Manage security modules
threatcrush store        # Browse the module marketplace
threatcrush update       # Upgrade the CLI using the supported path

Features

| Feature | Description | |---------|-------------| | 🔍 Live Attack Detection | Tails nginx, auth, syslog and journald, and polls inbound connections to the ports you serve. Detects SQLi, XSS, path traversal, RFI, SSH brute force, port scans, SYN floods, DNS tunneling. | | 🛡️ Code Security Scanner | Scan your codebase for vulnerabilities, hardcoded secrets, and misconfigurations. | | 💥 Pentest Checks | threatcrush pentest URL spot-checks security headers, CSP, CORS, cookie flags, server banners, directory listings and error leaks, then probes for SQL errors, path traversal and unsafe HTTP methods. | | 🔀 Network Monitor | Polls conntrack/ss every 5 s for inbound TCP connections to your listening ports. Flags port scans (10+ ports in 30 s) and SYN floods (50+ half-open from one source). No packet capture. | | 🔔 Real-time Alerts | Slack, email, webhook notifications the instant a threat is detected. | | ⚙️ systemd Daemon | Runs as a background service on your server. Auto-starts on boot, monitors 24/7. | | 📊 TUI Dashboard | Interactive terminal dashboard — htop for security. |

Modules

ThreatCrush uses a pluggable module system. Install from the marketplace or build your own:

threatcrush modules list                # List built-in and installed modules
threatcrush modules install ssh-guard   # Install a module
threatcrush modules install docker-monitor
threatcrush store search "firewall"     # Search marketplace
threatcrush store publish https://github.com/you/my-module  # Publish your own

Built in

| Component | What it covers | |-----------|----------------| | log-watcher | nginx access log + syslog — 96 OWASP CRS rules (PL1: SQLi, XSS, path traversal, RFI, RCE, PHP/Java injection, SSRF, scanners) + 1 ThreatCrush rule (OS files in the path) scored on every request | | ssh-guard | auth.log / secure — failed logins, brute force, root logins, user enumeration | | user-journal | journald — the systemd journal | | network-monitor | Inbound connections to your listening ports — port scans, SYN floods | | dns-monitor | Resolver logs (systemd-resolved, dnsmasq, bind, Pi-hole) — DNS tunneling, DGA detection | | threatcrush scan | Vulnerabilities, secrets, dependency CVEs (OSV.dev, with --deps) | | threatcrush pentest | Header, CORS, cookie, SQL-error, path-traversal and HTTP-method checks | | auto-defend | Bans via fail2ban, nftables or iptables | | alerts | Slack, Discord, email, webhook, PagerDuty |

Community Modules

Build and sell your own modules on the ThreatCrush marketplace:

  • docker-monitor — Container escape detection
  • k8s-watcher — Kubernetes cluster security
  • honeypot — Deploy decoy services
  • geo-blocker — Block traffic by country/ASN
  • compliance-reporter — SOC2, HIPAA, PCI-DSS reports

Configuration

threatcrush init                    # Auto-detect & generate config
threatcrush init --offline          # Same, without signing in (scripts, CI, containers)

Config lives at /etc/threatcrush/threatcrushd.conf with module configs in /etc/threatcrush/threatcrushd.conf.d/.

Cloud dashboard

The daemon reports to your ThreatCrush dashboard once the machine is logged in and linked to a server there:

threatcrush login
threatcrush servers link               # reuses the dashboard server with this hostname, or registers one
threatcrush servers link --org acme --name web-1
threatcrush status                     # shows the link
threatcrush servers unlink             # stop reporting

A running daemon picks up link and unlink within a minute; no restart. It then:

  • uploads detections at or above [cloud] min_severity (rule detections, plus events from modules no rule reads, such as dns-monitor), batched (100 events or every 10 s), and every ban and unban the daemon makes;
  • sends a heartbeat every 60 s with its version and hostname;
  • runs the threatcrush harden checks a minute after it starts and every 24 h, and uploads the findings (threatcrush harden uploads too; --no-upload skips it);
  • every 15 s, picks up blocks and unblocks queued on the dashboard and applies them through auto-defence, so protected and allowlisted addresses and dry-run apply as they do locally;
  • every 5 min, adds the organization's IP/CIDR allowlist to the never-block set.

Uploads never hold up detection or a ban. While the dashboard is unreachable, events wait in a spool (/var/lib/threatcrush/cloud-spool.jsonl, or ~/.threatcrush/state/ for a user daemon) of at most 10,000 events / 20 MB, oldest dropped first, which survives a restart and is sent when the dashboard answers again. The daemon uses the login of the user it runs as (/root/.threatcrush/config.json for the system service) and refreshes the session itself; if the refresh token is refused, it logs that threatcrush login is needed and keeps spooling.

[cloud]
enabled = true            # false: the daemon neither reports to nor takes actions from the dashboard
min_severity = "medium"   # info | low | medium | high | critical

Pricing

The CLI is MIT-licensed (see License). For pricing, contact us for a quote.

Browser Extension

Monitor security from your browser:

  • Chrome — Chrome Web Store (coming soon)
  • Firefox — Firefox Add-ons (coming soon)
  • Safari — Coming soon

Features: scan any site, real-time alerts, security headers check, dashboard popup.

Links

License

MIT © Profullstack, Inc.