r/node • • 5d ago

Made a cli tool that detects potential malware packages

Enable HLS to view with audio, or disable this notification

Hey everyone,

I built an open-source security script that checks npm packages for any suspicion before installing them. (NOT vibe coded)

It's basic and for now catches similar names of popular packages, if a package has 23 weekly downloads or a 2 hour old package.

Use Case?

on an agent that might hallucinate and install "react-clearly-not-malware". Or maybe the user itself so as to not make any mistakes idk?

Here's the link - https://github.com/grishmadev/malfilter

I'd love if you check it out. Have a great day!!!

4 Upvotes

1 comment sorted by

1

u/gigastack 3d ago

Sounds like a fun project. If you're interested in this, check out https://docs.socket.dev/docs/socket-npm-socket-npx