{"slug":"npm-postinstall-attack-scanner","title":"npm-postinstall-attack-scanner","description":"Detect npm supply chain attacks that use the postinstall + hidden dependency pattern to deliver malware. Built in response to the axios maintainer account takeover (2026-03-31). Scans lockfiles, ode_modules, postinstall scripts, version ranges, and npm cache across 5 phases. Returns actionable remediation steps when issues are found.","developer":null,"category":null,"reported_installs":null,"active":true,"first_seen_at":"2026-10-03T22:13:33.942Z","last_seen_at":"2026-10-11T18:00:01.991Z","last_changed_at":"2026-10-03T22:13:33.942Z","platform":"claude","sources":["Community"],"works_with":["Claude Code"],"marketplace_url":null,"repository_url":"https://github.com/aliksir/npm-postinstall-attack-scanner.git","web_data":{},"github_data":{},"catalog_sources":{"community":[{"name":"npm-postinstall-attack-scanner","source":{"sha":"833d1d06fbb50fcc185c182b5e771914cd4cebc2","url":"https://github.com/aliksir/npm-postinstall-attack-scanner.git","source":"url"},"homepage":"https://github.com/aliksir/npm-postinstall-attack-scanner","description":"Detect npm supply chain attacks that use the postinstall + hidden dependency pattern to deliver malware. Built in response to the axios maintainer account takeover (2026-03-31). Scans lockfiles, ode_modules, postinstall scripts, version ranges, and npm cache across 5 phases. Returns actionable remediation steps when issues are found."}]}}