Togoder security

Guides

Supply-chain security, explained

Command-level guides to spotting malicious packages, locking down install scripts and keeping dependencies safe in CI. Written for engineers, not auditors.

Start here

How to check if an npm package is malicious

npm audit tells you whether a package has a known advisory. It cannot tell you whether the version you are about to install was published yesterday with a credential stealer in its postinstall hook. This guide is the manual checklist we use, then how to automate it.

Detection7 min read
  • npm audit only reports packages that already have a published advisory; it does not inspect code, so brand-new malware passes it.
  • The highest-risk part of any npm package is its preinstall, install and postinstall scripts, which run automatically with your user's permissions.
  • Always inspect the published tarball, not the GitHub repository, because what is on the registry can differ from the source repo.

How Togoder Security scans packages

What the AI reviewer looks for, how files are triaged and cached, and where automated review falls short.