npm-postinstall-attack-scanner

PackSecurity

Scans an npm project for malicious install scripts and hidden dependencies used in supply chain attacks.

Unavailable. Delivery for this kind is on the roadmap — not serving yet.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

About this app

Detect npm supply chain attacks that use the postinstall + hidden dependency pattern to deliver malware. Built in response to the axios maintainer account takeover (2026-03-31). Scans lockfiles, ode_modules, postinstall scripts, version ranges, and npm cache across 5 phases. Returns actionable remed

Signals

GitHub stars
4k
Forks
312
Last commit
Aug 2026
Advanced
Item type
plugin
Key
anthropics-claude-plugins-community-npm-postinstall-1qxyc5o
Source
github.com/anthropics/claude-plugins-community