npm supply chain security
An npm install hook runs code before the package is ever imported. Extuno runs those hooks in a sandbox and diffs each release against the one before it, so typosquats, dependency confusion, and poisoned updates come back with evidence.
Why is npm a frequent target?
Most of a dependency tree is transitive, so one compromised package several levels down reaches projects that never named it. Install scripts compound that: a postinstall hook runs before anything imports the package. At npm's scale, both are worth attacking.
What npm attacks does Extuno catch?
Typosquatting and dependency confusion, malicious preinstall and postinstall hooks, credential and token exfiltration, crypto wallet drainers, and the poisoned-update pattern where a trusted package turns malicious in a later release.
How does Extuno analyze an npm package?
It resolves and unpacks the version, reads it with the static rule set, runs the install lifecycle in a sandbox to see what the hooks do, and diffs against the prior version so a new outbound channel or install-time payload is flagged.