Lateos/NPM-scan – open-source NPM supply chain scanner, v0.18.3
NPM supply chain scanner competing against Socket, Snyk, and npm audit.
Scan your code and infrastructure for quantum-vulnerable cryptography
Context-aware crypto risk: knows MD5 in UUID differs from MD5 in passwords.
Security engineers, DevSecOps teams, infrastructure/AppSec leads
Trivy · Snyk · GitGuardian
NPM supply chain scanner competing against Socket, Snyk, and npm audit.
Security scanner for Q-Day migration when Snyk doesn't track this yet.
Dedicated PQC scanner for TLS and SSH when testssl.sh lags behind.
Real-world bug bounty wins ($625+), but dependency confusion detection is a known category.
Blocks malicious packages at install-time before AI agents execute them on your machine.
Wraps native audits (npm audit, cargo audit) + license scanning, but Snyk and Dependabot already do this.