Skip to main content
Glama
tylerscomic-lab

npm-supply-chain-audit-mcp

npm-supply-chain-audit-mcp

License: MIT Live on MCPize

An MCP server that audits package.json for the real mechanisms behind actual npm supply-chain incidents — typosquatting and malicious install scripts — not a generic vulnerability-database lookup.

What it catches

Typosquatting. Dependency names within 1-2 character edit distance of one of the npm registry's most-depended-on packages (lodash, express, react, axios, and ~90 others) — the actual real targets of typosquat campaigns, since attackers go after the packages with the largest install base. lodahs, expres, reqeust all flag; an unrelated, genuinely distinct package name doesn't.

Malicious install scripts. preinstall/install/postinstall hooks run automatically on npm install, before any of the package's own code is ever reviewed — the actual delivery mechanism behind real incidents (event-stream 2018, ua-parser-js 2021, and others since). Flags scripts that pipe a remote download directly into a shell, and scripts that decode an obfuscated base64 payload before running it.

Unpinned versions. Dependencies on * or latest pull in whatever gets published next, silently, with no diff in your repo to explain why your dependency tree changed.

Related MCP server: npm-guardian

Tools

audit_package_json

Full audit of a package.json file.

check_package_name

Focused typosquat check on a single package name.

Use it

Hosted (recommended): MCPize — free tier, $7/mo Pro.

Self-host:

npm install
node server.js

Part of a small suite

secrets-leak-audit-mcp, mcp-trust-audit-mcp, github-actions-audit-mcp, dockerfile-audit-mcp.

License

MIT

Update 1.1.0 (2026-10-01)

  • New tools inspect_package_live and audit_dependencies_live: look packages up on the live npm registry. Flags names that do not exist (hallucinated or mistyped), brand-new low-traffic packages, install scripts, deprecated releases and typosquats.

Related MCP Connectors

Related MCP Servers

  • A
    license
    B
    quality
    C
    maintenance
    Enables security scanning for npm dependencies by checking manifest and lockfiles against the OSV.dev and Socket.dev vulnerability databases. It provides tools to detect vulnerabilities in specific packages and retrieve detailed technical reports for identified security issues.
    3
    15 npm
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Audits npm packages for supply-chain attacks (typosquatting, malicious install scripts, credential exfiltration) before installation, returning a SAFE/SUSPICIOUS/DANGEROUS verdict.
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Audits your package-lock.json for supply-chain attacks before install. Cross-checks every resolved entry against the live npm registry to detect integrity mismatches, new install scripts, and other malicious signals.
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Enables AI coding agents and CI to vet npm dependencies before they reach the lockfile, flagging hallucinated, slopsquatted, or otherwise risky packages with evidence-backed verdicts.
    3
    68 npm
    4
    MIT