Package registrynpm

npm install runs code. Extuno runs it in a sandbox first.

The payload in a poisoned npm release runs at install time, from a postinstall script in a dependency you never chose directly. Extuno diffs each published version, then runs the install hooks in a sandbox. Static, dynamic, and AI analysis run on every scan.

In shortTo check a npm package for supply-chain risk, scan the published artifact, not just the source, and compare each new version against the last. Extuno runs static analysis, a dynamic sandbox, and AI review across every npm release, then reports evidence on every finding.
npm - live inspectionexample
event-stream 3.3.6
npm package
3.3.5->3.3.6
Static
Dynamic
AI
Analyzing update
What Extuno catches in npm

Every finding is backed by evidence.

Each finding names the change, why it is dangerous, and the recommended action.

Diff finding

Malicious postinstall

A postinstall script added on update runs code on every install.

Critical
Diff finding

Transitive poisoning

A deep transitive dependency, not your direct one, carries the payload.

Critical
Diff finding

New network on install

The package contacts an external host during installation.

Review
See it on a poisoned update

The payload hides in a transitive dependency

Extuno walks the tree, runs each install hook in a sandbox, and flags the one that beacons out.

  • + Vulnerability and secret-leak testing on every version
  • + Static analysis reads the package without running it
  • + Dynamic sandbox runs it live and records behavior
  • + AI code analysis reads the full source and correlates the change against prior versions
How it works
your-app
@acme/utils 4.17.21
@acme/color-log 5.3.0
build-tools 2.1.0
flatmap-stream 0.1.1postinstall
flatmap-streamnpmjs-cdn.co

Scan your first npm package free.

5 free credits on signup. One credit per scan, no card required.

FAQ

Common questions

Does Extuno support npm?

Yes. Extuno scans npm with static analysis, a dynamic sandbox, and AI code analysis, and diffs every version to catch one that was clean but poisoned through an update.

How does Extuno scan npm?

Extuno acquires the published npm artifact, reads it statically with 1100+ rules, runs it in a network-segmented sandbox, reviews the source with AI, and diffs it against the prior version. The finding names the file, the change, why it is dangerous, and the fix.

What does Extuno catch in npm?

Leaked secrets, obfuscated or malicious code, dangerous permissions and APIs, exfiltration and command-and-control behavior, and the headline signal: a version that turns malicious after an update.