npm-supply-chain-audit-mcp
Audits package.json dependencies and package names against the npm registry, flagging typosquats, malicious install scripts, unpinned versions, and live registry issues such as nonexistent, brand-new, deprecated, or suspicious packages.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@npm-supply-chain-audit-mcpaudit my package.json for typosquats and malicious install scripts"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
npm-supply-chain-audit-mcp
An MCP server that audits package.json for the real mechanisms behind actual npm supply-chain incidents —
typosquatting and malicious install scripts — not a generic vulnerability-database lookup.
What it catches
Typosquatting. Dependency names within 1-2 character edit distance of one of the npm registry's
most-depended-on packages (lodash, express, react, axios, and ~90 others) — the actual real targets of
typosquat campaigns, since attackers go after the packages with the largest install base. lodahs, expres,
reqeust all flag; an unrelated, genuinely distinct package name doesn't.
Malicious install scripts. preinstall/install/postinstall hooks run automatically on npm install,
before any of the package's own code is ever reviewed — the actual delivery mechanism behind real incidents
(event-stream 2018, ua-parser-js 2021, and others since). Flags scripts that pipe a remote download directly
into a shell, and scripts that decode an obfuscated base64 payload before running it.
Unpinned versions. Dependencies on * or latest pull in whatever gets published next, silently, with no
diff in your repo to explain why your dependency tree changed.
Related MCP server: npm-guardian
Tools
audit_package_json
Full audit of a package.json file.
check_package_name
Focused typosquat check on a single package name.
Use it
Hosted (recommended): MCPize — free tier, $7/mo Pro.
Self-host:
npm install
node server.jsPart of a small suite
secrets-leak-audit-mcp, mcp-trust-audit-mcp, github-actions-audit-mcp, dockerfile-audit-mcp.
License
MIT
Update 1.1.0 (2026-10-01)
New tools
inspect_package_liveandaudit_dependencies_live: look packages up on the live npm registry. Flags names that do not exist (hallucinated or mistyped), brand-new low-traffic packages, install scripts, deprecated releases and typosquats.
This server cannot be deployed
Maintenance
Related MCP Connectors
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Audit GitHub repos for malicious and supply-chain code before you depend on them.
x402-gated safety checker for npm/PyPI packages before you npm install / pip install.
Supply chain risk scoring for npm, PyPI, Cargo, and Go. 9 tools. Behavioral signals.
Related MCP Servers
- AlicenseBqualityCmaintenanceEnables security scanning for npm dependencies by checking manifest and lockfiles against the OSV.dev and Socket.dev vulnerability databases. It provides tools to detect vulnerabilities in specific packages and retrieve detailed technical reports for identified security issues.315 npmMIT
- AlicenseNot gradedqualityCmaintenanceAudits npm packages for supply-chain attacks (typosquatting, malicious install scripts, credential exfiltration) before installation, returning a SAFE/SUSPICIOUS/DANGEROUS verdict.MIT
- AlicenseNot gradedqualityDmaintenanceAudits your package-lock.json for supply-chain attacks before install. Cross-checks every resolved entry against the live npm registry to detect integrity mismatches, new install scripts, and other malicious signals.MIT
- AlicenseAqualityAmaintenanceEnables AI coding agents and CI to vet npm dependencies before they reach the lockfile, flagging hallucinated, slopsquatted, or otherwise risky packages with evidence-backed verdicts.368 npm4MIT