Check npm maintainer blast radius
check_maintainer_blast_radiusGiven an npm username, lists the packages npm's maintainer: search index returns for that account and looks for a tight cluster of packages whose latest version was published within a short rolling window of each other — the shape of a compromised-account supply-chain attack, where a stolen credential is used on every package the account can publish to within hours (e.g. the September 2025 chalk/debug compromise, ~18 packages in ~2 hours). A large total package count is not itself a red flag; only a tight publish-time cluster is scored, weighted by its package count and combined weekly downloads/dependentsCount. Clusters mostly within one npm scope (a monorepo release) are dampened, and multiple clusters combine with diminishing returns. isCurrentMaintainer shows whether the account still maintains each package. avatarUrl is a proxied Gravatar image (null if no email is on record). Natural follow-up to check_maintainer_changes: call this with a newly added maintainer's username to see whether the same account touched other packages around the same time. Limitations: npm's search index can lag or omit packages; results are capped at 250 packages ranked by relevance, not recency (see resultsTruncated/totalPackagesFound); lastPublished reflects only each package's latest version. npmscanUrl is the account's npmscan profile; npmProfileUrl is its npmjs.com page.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| maintainerUsername | Yes | Exact npm username, e.g. "sindresorhus" — as shown at npmjs.com/~username. Not an email address, not a package name or scope. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| note | Yes | ||
| clusters | Yes | ||
| findings | Yes | ||
| packages | Yes | ||
| riskTier | Yes | ||
| avatarUrl | Yes | ||
| npmscanUrl | Yes | ||
| totalScore | Yes | ||
| npmProfileUrl | Yes | ||
| packagesReturned | Yes | ||
| resultsTruncated | Yes | ||
| clusterWindowHours | Yes | ||
| maintainerUsername | Yes | ||
| totalPackagesFound | Yes |