Scanner to check if you are affected by the axios supply chain attack
Forensic triage CLI with verdict system for axios IOC detection.
Run [ npm i ] safely, audit installs inside a docker container.
Docker isolation + tcpdump catches malicious npm installs before they touch your machine.
Node.js developers, security-conscious teams
Socket.dev · npm audit · Snyk
Forensic triage CLI with verdict system for axios IOC detection.
Better than scrolling Sonatype blogs when you need a quick npm security checklist.
NPM supply chain scanner competing against Socket, Snyk, and npm audit.
Behavioral malware scanning before install, unlike pip-audit.
Speculative protocol for package quarantine without a reference implementation or registry buy-in.
Catches .pth injection vectors from the litellm attack when Snyk and Dependabot miss them.