Autonomous “Shai-Hulud” engine that ingests malicious NPM package advisories from OSV, tracks versions and metadata, and maintains a continuously updated threat intelligence database.
-
Updated
Oct 1, 2026 - JavaScript
Autonomous “Shai-Hulud” engine that ingests malicious NPM package advisories from OSV, tracks versions and metadata, and maintains a continuously updated threat intelligence database.
World-class security standard for npm packages. Automated threat detection, supply chain analysis, and 0-100 security scores. Because in 2025, we can do better than the Wild West
Supply-chain security and dependency analysis tool for the npm ecosystem
Scans the real npm publish tarball before release and blocks leaks like source maps, secrets, internal files, and suspicious oversized artifacts.
Stop coding agents from installing hallucinated, typosquatted, malicious or freshly hijacked npm and PyPI packages.
Keyless MCP server giving AI agents software supply-chain intel across npm, PyPI and crates.io — versions, popularity, dependencies, health and advisories. No API keys.
Offline-first CLI and GitHub Action for dependency health checks across npm, Python, Rust, and Go: vulnerabilities, risky scripts, typosquatting, stale packages, licenses, and baseline-aware CI reports.
To associate your repository with the package-security topic, visit your repo's landing page and select "manage topics."