Guides
Supply-chain security, explained
Command-level guides to spotting malicious packages, locking down install scripts and keeping dependencies safe in CI. Written for engineers, not auditors.
Start here
How to check if an npm package is malicious
npm audit tells you whether a package has a known advisory. It cannot tell you whether the version you are about to install was published yesterday with a credential stealer in its postinstall hook. This guide is the manual checklist we use, then how to automate it.
- npm audit only reports packages that already have a published advisory; it does not inspect code, so brand-new malware passes it.
- The highest-risk part of any npm package is its preinstall, install and postinstall scripts, which run automatically with your user's permissions.
- Always inspect the published tarball, not the GitHub repository, because what is on the registry can differ from the source repo.
npm supply chain attacks: types, incidents, defenses
npm supply chain attacks explained: typosquatting, dependency confusion, account takeover, protestware and worms, from event-stream to Shai-Hulud.
03npm install scripts security: postinstall risks & fixes
npm install scripts security: why postinstall hooks are a top malware vector, how to audit them, and how npm, pnpm, Yarn, Bun, pip and cargo differ.
04npm audit vs source code scanning: what each catches
npm audit vs source code scanning: how advisory databases like npm audit, Dependabot and OSV compare with behavioral analysis of code, and why you need both.
05Scan your lockfile in CI: dependency malware checks
How to scan a lockfile in CI for malicious dependencies: GitHub Actions example, npm ci, lockfile-lint, ignore-scripts, pinning and scanning only changes.
How Togoder Security scans packages
What the AI reviewer looks for, how files are triaged and cached, and where automated review falls short.