Malicious package scanner for npm, PyPI, crates.io & more
Read every line your dependencies ship. Before you install them.
Advisories only catch malware after someone reports it. We download every package in your lockfile and have an AI model read the actual source, looking for install-time payloads, credential theft, exfiltration and backdoors.
or upload a lockfile to scan a whole project · free quote, no account
Install script base64-decodes a URL and POSTs process.env, including NPM_TOKEN and AWS keys, to it.
Example output
How it works
Three steps, priced before you pay
-
1
Upload
Drop in a lockfile or manifest, or name a single package. We resolve the full dependency tree the way your installer would.
-
2
Get a fixed quote
Every package is downloaded and hashed. Files anyone has scanned before are free, so you only pay for new code. The quote is what you're charged.
-
3
Read the findings
Results by severity, with the package, file and line, what the code does and what to do about it.
What it looks for
The things a CVE feed won't tell you
Install-time payloads
npm lifecycle scripts, setup.py and .pth files, build.rs, Go init() and code that runs on import.
Credential theft
Reads of env vars, SSH keys, .npmrc tokens, browser profiles and crypto wallets.
Exfiltration
Suspicious network requests and data sent to external servers.
Obfuscated code
Encoded blobs, eval of decoded strings and code fetched and executed at runtime.
Backdoors
Reverse shells, spawned processes and file writes outside the package.
Wallet drainers & miners
Seed-phrase theft, address rewriting and hidden cryptocurrency mining.
- npm
- package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lock, package.json
- Python
- poetry.lock, uv.lock, Pipfile.lock, requirements.txt, pyproject.toml
- Rust
- Cargo.lock
- Go
- go.mod, go.sum
- Ruby
- Gemfile.lock
- PHP
- composer.lock
Pricing
Pay for new code, not for the same lodash twice
Pay per scan
Quoted per scan USDC on Base
- No account, connect a wallet and go
- Priced by tokens, fixed before you pay
- Cached files cost nothing
- Works for agents over x402
Monthly access
Flat monthly via Ko-fi
- Unlimited lockfiles within a token budget
- API keys for CI and scripts
- No wallet needed
- Pay early to stack months
For CI and agents
One HTTP call
POST a lockfile and you get a 402 with the price. Any x402 client pays and
retries automatically, so an AI agent can vet a package before it installs it.
# returns 402 with the price curl -X POST https://security.togoder.click/api/paid-scan \ -F "file=@package-lock.json" # or a single package and its dependency tree curl -X POST https://security.togoder.click/api/paid-scan \ -H "Content-Type: application/json" \ -d '{"ecosystem":"pypi","packageName":"requests"}'
Public reports
Every scan becomes a free security report
Recently scanned
Browse all npm reportsRecently flagged
Flagged packages trackerLast scan Oct 6, 2026.
FAQ
Questions people ask before they scan
How do I check if an npm package is malicious?
Enter the package name or upload your lockfile at https://security.togoder.click/scan. Togoder Security downloads every package, never runs it, and has an AI model read each source file for install-time payloads, credential theft, exfiltration, obfuscation and backdoors. Packages someone already scanned have a free public report, for example https://security.togoder.click/npm/express.
How is this different from npm audit?
npm audit only reports vulnerabilities that are already in an advisory database. Source review reads the code itself, so it can flag a malicious new release before anyone has reported it. Use both.
Which ecosystems and lockfiles are supported?
npm (package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lock, package.json), Python (poetry.lock, uv.lock, Pipfile.lock, requirements.txt, pyproject.toml), Rust (Cargo.lock), Go (go.mod, go.sum), Ruby (Gemfile.lock) and PHP (composer.lock).
How much does a scan cost?
Parsing and the price quote are free. You pay only for files nobody has scanned before, either per scan in USDC on Base via x402 or with a flat monthly plan that includes API keys.
Can AI agents use it?
Yes. POST a lockfile or package name to https://security.togoder.click/api/paid-scan; the server answers HTTP 402 with a price and any x402 client pays and retries automatically, so an agent can vet a dependency before installing it.
See what's in your node_modules
Parsing and quoting are free. You only pay if you run the scan.