npm Supply Chain
Security Scanner

Automated static analysis of npm packages. Detect lifecycle script attacks, obfuscated code, credential harvesting, and version tampering in seconds.

Scan a Package

Enter any npm package name. Optionally specify a version to scan.

Receive a copy of the scan report via email.

Have a credit code? Enter it here. Otherwise, free scans are available.

0
View Full Report

What We Detect

Lifecycle Scripts

preinstall, postinstall, and install scripts that execute code during npm install.

Code Obfuscation

_0x variable patterns, eval(), new Function(), and Base64 encoded payloads.

Credential Theft

Access to AWS keys, GitHub tokens, NPM tokens, and other sensitive env vars.

Version Tampering

Abnormal size changes, new maintainers, and new dependencies between versions.

Network Exfiltration

Outbound HTTP calls and child_process usage in install scripts.

Hardcoded IPs

Suspicious IP addresses embedded in package code.

Pricing

Free
Community Scan
Rate-limited. No email delivery.
Perfect for quick checks.

Need bulk scans? Buy a credit bundle for volume pricing.

View real case studies of compromised packages →