A Snyk alternative for the malicious package, not just the CVE.
Snyk is strong on known-CVE SCA. If your worry is the package that is malicious right now, post-install scripts, suspicious maintainer handoffs, typosquats, Dralvia is the alternative built around supply-chain compromise.
Repository security
See Dralvia in action.
Review source packages for SBOM, secret, dependency, and provenance risks in one workflow.
- Submit a supported repository package
- Track the review
- Export evidence into existing AppSec workflows
This preview shows the Dralvia workspace. Sign in to see your own scans, alerts, and activity.

What you gain adding or switching to Dralvia.
Malicious-package focus
Post-install and lifecycle-script analysis, deobfuscation, and maintainer-change signal, the active-compromise lane CVE lists miss.
Typosquat & confusion
Edit-distance neighbours and dependency-confusion checks against the registry.
Full transitive walk
Dralvia scores every node in the tree and surfaces the deepest finding, not just direct dependencies.
Advisory cross-reference
Known-CVE context via OSV.dev sits alongside the compromise signal, so you get both views.
Evidence for procurement
An EvidencePack you can attach to the procurement or merge record.
Honest answers.
For known-CVE SCA and SAST, Snyk is strong, keep it if you rely on it. Dralvia complements or replaces it for active supply-chain compromise detection.
Try Dralvia as your Snyk alternative.
Run it on your real work and see the verdict, the evidence, and the export.