← Browse
npm-postinstall-attack-scanner
aliksir ★ 1
Detects npm supply chain attacks using the postinstall + hidden dependency pattern by scanning for known compromised versions, malicious dependencies, suspicious install scripts, dangerous version ranges, and C2 domain indicators. Built in response to the axios maintainer account takeover incident, it performs six phases of analysis and integrates with GitHub Actions for continuous monitoring.
Install
> /plugin marketplace add aliksir/npm-postinstall-attack-scanner
> /plugin install npm-postinstall-attack-scanner
Source: https://github.com/aliksir/npm-postinstall-attack-scanner
What it's made of
no extra components
- Commands
- 0
- Agents
- 0
- Skills
- 0
- MCP servers
- 0
- Hooks
- 0
What it needs & plugs into
- API keys
- none
- Paid services
- none detected
- External tools
- none
- Talks to
- nothing external detected
Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.
Is this your plugin?
Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (aliksir).