npm-supply-chain-audit-mcp
README.md
# npm-supply-chain-audit-mcp
[](LICENSE)
[](https://mcpize.com/mcp/npm-supply-chain-audit-mcp)
An MCP server that audits `package.json` for the real mechanisms behind actual npm supply-chain incidents —
typosquatting and malicious install scripts — not a generic vulnerability-database lookup.
## What it catches
**Typosquatting.** Dependency names within 1-2 character edit distance of one of the npm registry's
most-depended-on packages (`lodash`, `express`, `react`, `axios`, and ~90 others) — the actual real targets of
typosquat campaigns, since attackers go after the packages with the largest install base. `lodahs`, `expres`,
`reqeust` all flag; an unrelated, genuinely distinct package name doesn't.
**Malicious install scripts.** `preinstall`/`install`/`postinstall` hooks run automatically on `npm install`,
before any of the package's own code is ever reviewed — the actual delivery mechanism behind real incidents
(`event-stream` 2018, `ua-parser-js` 2021, and others since). Flags scripts that pipe a remote download directly
into a shell, and scripts that decode an obfuscated base64 payload before running it.
**Unpinned versions.** Dependencies on `*` or `latest` pull in whatever gets published next, silently, with no
diff in your repo to explain why your dependency tree changed.
## Tools
### `audit_package_json`
Full audit of a package.json file.
### `check_package_name`
Focused typosquat check on a single package name.
## Use it
**Hosted (recommended):** [MCPize](https://mcpize.com/mcp/npm-supply-chain-audit-mcp) — free tier, $7/mo Pro.
**Self-host:**
```bash
npm install
node server.js
```
## Part of a small suite
[secrets-leak-audit-mcp](https://github.com/tylerscomic-lab/secrets-leak-audit-mcp),
[mcp-trust-audit-mcp](https://github.com/tylerscomic-lab/mcp-trust-audit-mcp),
[github-actions-audit-mcp](https://github.com/tylerscomic-lab/github-actions-audit-mcp),
[dockerfile-audit-mcp](https://github.com/tylerscomic-lab/dockerfile-audit-mcp).
## License
MIT
## Update 1.1.0 (2026-10-01)
- New tools `inspect_package_live` and `audit_dependencies_live`: look packages up on the live npm registry. Flags names that do not exist (hallucinated or mistyped), brand-new low-traffic packages, install scripts, deprecated releases and typosquats.
This server cannot be deployed
Maintenance
ActivityMaintained
ResponsivenessNo issues