2,008,996 packages matching “malicious-code”
anti-trojan-source
v1.13.0 · 26 days ago
Detect trojan source attacks that employ unicode bidi attacks to inject malicious code
No known vulnerabilities
lavamoat
v11.1.6 · 9 days ago
`lavamoat` is a NodeJS runtime where modules are defined in [SES][SesGithub] Compartments. It aims to reduce the risk of malicious code in the app dependency graph, known as "software supply chain attacks".
No known vulnerabilities
@ondrej-merkun/skill-audit
v0.2.1 · 4 months ago
Scan AI agent skills for prompt injection and malicious code
No known vulnerabilities
nullvoid
v2.1.0 · 10 months ago
Detect malicious code
No known vulnerabilities
@pwddd/skills-scanner
v4.0.0 · 6 months ago
OpenClaw Skills security scanner plugin - detect malicious code, data exfiltration, and prompt injection
No known vulnerabilities
@repoguard/scanner
v1.0.4 · 4 days ago
Security scanner for detecting malicious code patterns in repositories
No known vulnerabilities
mitnick
v1.0.2 · 6 months ago
Pre-install security analysis CLI for npm packages. Analyze packages before installation to detect vulnerabilities, malicious code, typosquatting, and supply chain attacks.
No known vulnerabilities
@rahulmalik/npm-safe
v2.0.4 · 9 months ago
Comprehensive security firewall for Node.js applications - Blocks 100% of supply chain attacks, credential exfiltration, and malicious code execution
No known vulnerabilities
skill-checker
v0.2.0 · 6 months ago
Security checker for Claude Code skills - detect injection, malicious code, and supply chain risks before installation
No known vulnerabilities
@appservicescomponents/chore
v0.0.1 · 4 years ago
This is only published to prevent duplicate or malicious code
No known vulnerabilities
@appservicescomponents/usemendix
v0.0.2 · 4 years ago
This is only published to prevent duplicate or malicious code
No known vulnerabilities
open-eval
v1.0.0 · 6 years ago
Eval untrusted and possibly malicious code.
No known vulnerabilities
dsh-security-guard
v0.1.0-rc.7 · 1 month ago
Static and runtime security guard for the DeepSeek Harness: scans plugins and workspaces for malicious code, context injection and token waste (block/warn/clean), intercepts dangerous runtime tool calls and prompt steps, and exposes /scan, plugin_scan, th
No known vulnerabilities
@arunmm8335/mcpguard
v0.1.0 · 2 months ago
Security scanner for MCP servers — detect tool poisoning, malicious code patterns, and supply-chain risks before your AI agents execute them.
No known vulnerabilities
braces
v3.0.3 · 2 years ago
Bash-like brace expansion, implemented in JavaScript. Safer than other brace expansion libs, with complete support for the Bash 4.3 braces specification, without sacrificing speed.
1 high
npm-scan-plus
v1.1.1 · 4 months ago
Security scanner for npm packages - pre and post-install scanning for malicious code, supply chain attacks, and obfuscated code
No known vulnerabilities
@art-ws/config-eslint
v2.0.8 · 1 month ago
Versions 2.0.4 and 2.0.5 of this package were published with malicious code on 15 September 2025, when the npm account that publishes it was compromised in the Shai-Hulud supply-chain campaign. The registry removed them from npm; they cannot be installed.
No known vulnerabilities
@yangyixxxx/skill-guard
v0.1.1 · 2 months ago
Local-first security scanner for AI Skills (Anthropic Skill bundles, Newmax, OpenClaw, MCP, GPTs Actions). Catches malicious code, supply-chain attacks, and prompt injection — pure static analysis, sub-2s, zero LLM cost.
No known vulnerabilities
@art-ws/config-ts
v2.0.10 · 1 month ago
Versions 2.0.7 and 2.0.8 of this package were published with malicious code on 15 September 2025, when the npm account that publishes it was compromised in the Shai-Hulud supply-chain campaign. The registry removed them from npm; they cannot be installed.
No known vulnerabilities
@apollographql/graphql-playground-html
v1.6.29 · 5 years ago
GraphQL IDE for better development workflows (GraphQL Subscriptions, interactive docs & collaboration).
No known vulnerabilities