← Claude plugins
CLAUDE PLUGIN

npm-postinstall-attack-scanner

Publisher not specified · Claude Code

What this plugin does

Detect npm supply chain attacks that use the postinstall + hidden dependency pattern to deliver malware. Built in response to the axios maintainer account takeover (2026-03-31). Scans lockfiles, ode_modules, postinstall scripts, version ranges, and npm cache across 5 phases. Returns actionable remediation steps when issues are found.

Catalog observations

Sources
Community
Works with
Claude Code
Reported installs
Not provided
First observed
2026-10-03 22:13 UTC
Last observed
2026-10-11 18:00 UTC

Installation counts are reported by Claude Marketplace, not independently verified active users. Observation dates are not release dates. Pricing and account requirements must be checked with the publisher.

Install in Claude Code

Choose a source and review what the plugin adds before installing.

Community

/plugin marketplace add anthropics/claude-plugins-community
/plugin install npm-postinstall-attack-scanner@claude-community

Claude Code installation documentation

Source evidence

Listing and manifest JSON

Descriptions and compatibility labels come from the linked sources. Where both sources match, the GitHub description is used because web summaries may be shortened. We have not independently tested the declared capabilities.