

NPMScan
NPMScan is a security analysis tool for the JavaScript ecosystem. It scans npm packages for malicious behavior and supply chain risks that are often invisible to developers. The scanner inspects scripts, dependencies, encoded payloads, metadata, and common attack patterns used...
Cost / License
- Free
- Proprietary
Platforms
- Online
Features
Properties
- Privacy focused
Features
- Malware Analysis
- No Tracking
- No Logs
- No registration required
- Dark Mode
- Ad-free
- NPM
NPMScan News & Activities
Recent activities
- block_hacks updated NPMScan
- block_hacks liked NPMScan
- block_hacks added NPMScan
- POX updated NPMScan
block_hacks added NPMScan as alternative to Snyk, GitHub, Artemis Security Scanner and Mend Renovate
NPMScan information
What is NPMScan?
NPMScan is a security analysis tool for the JavaScript ecosystem. It scans npm packages for malicious behavior and supply chain risks that are often invisible to developers. The scanner inspects scripts, dependencies, encoded payloads, metadata, and common attack patterns used by threat actors targeting Node.js projects.
It highlights issues such as obfuscated code, unexpected install scripts, typosquat attempts, abandoned maintainers, and dependencies that may contain malware or crypto-drainer functionality. The goal is to give developers a fast way to understand the real risk level of any npm package before adding it to their project.
No setup required. Just enter a package name and get an instant risk report.






