PlugMyPlugin
← Browse

npm-postinstall-attack-scanner

aliksir ★ 1

Detects npm supply chain attacks using the postinstall + hidden dependency pattern by scanning for known compromised versions, malicious dependencies, suspicious install scripts, dangerous version ranges, and C2 domain indicators. Built in response to the axios maintainer account takeover incident, it performs six phases of analysis and integrates with GitHub Actions for continuous monitoring.

Security DevOps free prompt pack

Install

> /plugin marketplace add aliksir/npm-postinstall-attack-scanner
> /plugin install npm-postinstall-attack-scanner

Source: https://github.com/aliksir/npm-postinstall-attack-scanner

What it's made of

no extra components

Commands
0
Agents
0
Skills
0
MCP servers
0
Hooks
0

What it needs & plugs into

API keys
none
Paid services
none detected
External tools
none
Talks to
nothing external detected

Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.

Is this your plugin?

Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (aliksir).