
npm Supply Chain Audit
io.github.tylerscomic-labv1.1.0更新于 Oct 2, 2026
Check npm packages for typosquats, hallucinated names, install scripts and risky new releases.
概览
审计 npm 的 package.json,识别仿冒包名、可疑安装脚本、未固定版本以及注册表中的可疑条目。
- 功能
- 该服务器提供用于检查 npm 依赖清单供应链风险的工具,而非通用漏洞库查询。audit_package_json 对 package.json 做完整审计,check_package_name 针对单个包名做仿冒检查,较新的 inspect_package_live 和 audit_dependencies_live 则查询在线 npm 注册表。它会标记与高依赖量包名编辑距离在 1-2 个字符以内的名称、把远程下载直接管道到 shell 或先解码 base64 载荷的安装钩子,以及固定为 * 或 latest 的依赖。在线查询还会标记不存在、全新且下载量低、已弃用或疑似仿冒的包。
- 适用场景
- 适合在安装或合并前审查 JavaScript 项目的依赖,核实助手建议的包名是否真实存在,或在供应链事件后排查依赖树。它针对的是 npm 特有的仿冒包名和安装脚本风险,而不是通用漏洞扫描。
- 运行要求
- 托管方式为远程 streamable HTTP 端点;README 也说明可自行部署,需安装依赖并运行 node server.js,因此需要 Node.js。清单未声明认证、环境变量或请求头。在线注册表工具需要访问 npm 注册表的网络连接。README 提到有免费额度和付费 Pro 方案。
安装
在 SourceWeft 中
- 打开 控制台中的 npm Supply Chain Audit,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。
其他 MCP 客户端
把它添加到你客户端的 mcpServers 配置中。
{
"mcpServers": {
"npm-supply-chain-audit-mcp": {
"type": "http",
"url": "https://npm-supply-chain-audit-mcp.mcpize.run/mcp"
}
}
}README
npm-supply-chain-audit-mcp
[License: MIT] [Live on MCPize]
An MCP server that audits package.json for the real mechanisms behind actual npm supply-chain incidents —
typosquatting and malicious install scripts — not a generic vulnerability-database lookup.
What it catches
Typosquatting. Dependency names within 1-2 character edit distance of one of the npm registry's
most-depended-on packages (lodash, express, react, axios, and ~90 others) — the actual real targets of
typosquat campaigns, since attackers go after the packages with the largest install base. lodahs, expres,
reqeust all flag; an unrelated, genuinely distinct package name doesn't.
Malicious install scripts. preinstall/install/postinstall hooks run automatically on npm install,
before any of the package's own code is ever reviewed — the actual delivery mechanism behind real incidents
(event-stream 2018, ua-parser-js 2021, and others since). Flags scripts that pipe a remote download directly
into a shell, and scripts that decode an obfuscated base64 payload before running it.
Unpinned versions. Dependencies on * or latest pull in whatever gets published next, silently, with no
diff in your repo to explain why your dependency tree changed.
Tools
audit_package_json
Full audit of a package.json file.
check_package_name
Focused typosquat check on a single package name.
Use it
Hosted (recommended): MCPize — free tier, $7/mo Pro.
Self-host:
Part of a small suite
secrets-leak-audit-mcp, mcp-trust-audit-mcp, github-actions-audit-mcp, dockerfile-audit-mcp.
License
MIT
Update 1.1.0 (2026-10-01)
- New tools
inspect_package_liveandaudit_dependencies_live: look packages up on the live npm registry. Flags names that do not exist (hallucinated or mistyped), brand-new low-traffic packages, install scripts, deprecated releases and typosquats.
来源:README.md,提交 d9bebba
工具
0版本历史
1- v1.1.0最新Oct 2, 2026