NPM Scan

A fast security scanner that detects malicious or suspicious

Visit Website
November 16, 2025 I built NPM Scan: a simple tool to reveal what’s really inside npm packages

Over the last few years, the JavaScript ecosystem has turned into a supply-chain battlefield. Packages look harmless on the surface but hide obfuscated code, suspicious postinstall scripts, silent network calls, or maintainers who disappeared years ago. Most of us install dependencies without ever checking what we’re pulling into our codebase.

A few weeks ago I asked myself a simple question:

Why isn’t there a fast, dead-simple way to “x-ray” an npm package before trusting it?

I didn’t want a CLI, config files, or yet another security product that takes an afternoon to set up. I wanted a website where I could type a package name and instantly see all the red flags.

So I built NPM Scan → https://npmscan.com

What it does

  • Scans npm packages in seconds

  • Detects hidden scripts, obfuscated code, and suspicious patterns

  • Highlights inactive or unknown maintainers

  • Shows full file structure, metadata, and dependencies

  • Assigns a risk score based on real security signals

  • No install, no setup — just search and check

Why I built it

I’ve seen too many developers assume a package is safe because it has downloads or stars. That’s how supply-chain attacks spread. My goal was to make package security obvious, fast, and accessible, even for developers who don’t have time to dig through source code.

What’s next

I’m planning to add:

  • API access

  • GitHub PR bot integration

  • Automated scanning for your package.json

  • Alerts for newly compromised packages

I’d love feedback from the IndieHackers community.
What features would actually help you in your workflow?
Would you use this before adding a dependency?

If you want to try it: https://npmscan.com

Happy to answer questions about the build, stack, struggles, or the process behind it.

Comment

About

I built NPM Scan because the JavaScript ecosystem has a real supply-chain problem. Developers install packages every day without realizing how many of them contain hidden scripts, obfuscated code, or risky maintainers.