NPM Supply Chain Check

Detect known malicious npm package versions and install-time supply-chain indicators in repositories, lockfiles, and node_modules. Use when a user mentions an npm compromise, Shai-Hulud, the Keyv/cacheable incident, suspicious preinstall scripts, credential-stealing packages, or asks whether a JavaScript project was exposed to a package supply-chain attack. Do not use as a general CVE or license audit.

majiayu000 2fc5539 2 files · 7.8 KB Updated 567 repo stars

File contents

majiayu000/claude-skill-registry-data/tree/main/other/npm-supply-chain-check commit 2fc5539a42

Frequently asked questions

npx skillmds add majiayu000/npm-supply-chain-check