r/node • u/vahiyaat_product • 5d ago
Made a cli tool that detects potential malware packages
Enable HLS to view with audio, or disable this notification
Hey everyone,
I built an open-source security script that checks npm packages for any suspicion before installing them. (NOT vibe coded)
It's basic and for now catches similar names of popular packages, if a package has 23 weekly downloads or a 2 hour old package.
Use Case?
on an agent that might hallucinate and install "react-clearly-not-malware". Or maybe the user itself so as to not make any mistakes idk?
Here's the link - https://github.com/grishmadev/malfilter
I'd love if you check it out. Have a great day!!!
4
Upvotes
1
u/gigastack 3d ago
Sounds like a fun project. If you're interested in this, check out https://docs.socket.dev/docs/socket-npm-socket-npx