Skip to content
#

npm-security

Here are 29 public repositories matching this topic...

macOS Seatbelt sandbox CLI for developers. Protect credentials (SSH, AWS, GPG) from malicious npm packages, supply chain attacks, and untrusted build scripts. Deny-by-default filesystem isolation. Perfect for Claude Code agentic workflows with --dangerously-skip-permissions.

  • Updated Apr 27, 2026
  • Rust

Autonomous “Shai-Hulud” engine that ingests malicious NPM package advisories from OSV, tracks versions and metadata, and maintains a continuously updated threat intelligence database.

  • Updated Apr 28, 2026
  • JavaScript

Sentinel Package Manager blocks compromised packages BEFORE installation, preventing malicious code execution. Features: Pre-install blocking, command interception (npm/yarn/pnpm/bun), 795+ blacklist (Shai-Hulud), real-time checks (OSV/GitHub/Snyk), zero dependencies, auto-updates. Counters supply chain attacks.

  • Updated Dec 2, 2025
  • JavaScript

🛡️ Advanced NPM supply chain attack detection tool - Specialized in detecting Shai-Hulud compromise indicators with beautiful CLI interface and automated security reporting

  • Updated Sep 19, 2025
  • TypeScript

Security scanner for MCP (Model Context Protocol) servers. Detect prompt injection, secrets leaks, supply chain attacks, and vulnerabilities in MCP servers. CLI + MCP server mode.

  • Updated Apr 23, 2026
  • TypeScript

Threat intel package for Lazarus Group's 3-wave GitHub phishing campaign targeting developers (Mar-Apr 2026). YARA, Sigma, Suricata, Nuclei rules + STIX 2.1 bundle + ATT&CK Navigator layer + full C2 infrastructure map. Defensive use only.

  • Updated Apr 9, 2026
  • Python

Improve this page

Add a description, image, and links to the npm-security topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the npm-security topic, visit your repo's landing page and select "manage topics."

Learn more