Lateos/NPM-scan – open-source NPM supply chain scanner, v0.18.3
NPM supply chain scanner competing against Socket, Snyk, and npm audit.
Find out if your system was compromised by the recent axios supply chain attack.
Forensic triage CLI with verdict system for axios IOC detection.
DevOps engineers, security teams, developers auditing npm dependencies
npm audit · Snyk · Socket.dev
NPM supply chain scanner competing against Socket, Snyk, and npm audit.
Behavioral malware scanning before install, unlike pip-audit.
Catches .pth injection vectors from the litellm attack when Snyk and Dependabot miss them.
Triage tool for a real attack, but static IoC-matching won't catch adaptive threats.
First real supply-chain defense for AI agent ecosystems; catches nation-state-grade payloads.
Speculative protocol for package quarantine without a reference implementation or registry buy-in.