Server data from the Official MCP Registry
Check npm packages for typosquats, hallucinated names, install scripts and risky new releases.
About
Check npm packages for typosquats, hallucinated names, install scripts and risky new releases.
Remote endpoints: streamable-http: https://npm-supply-chain-audit-mcp.mcpize.run/mcp
Security Report
This is a well-designed npm supply-chain audit tool with proper input validation, reasonable scope, and legitimate security-focused functionality. The code is clean with good error handling. Minor concerns around timeout configuration and broad exception handling in network calls do not significantly impact security posture. Permissions (network_http, file operations via parameters) align with the tool's stated purpose of analyzing packages and querying the npm registry.
4 files analyzed · 4 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Install & Connect
Available as Local & Remote
This plugin can run on your machine or connect to a hosted endpoint. during install.
Documentation
View on GitHubFrom the project's GitHub README.
npm-supply-chain-audit-mcp
An MCP server that audits package.json for the real mechanisms behind actual npm supply-chain incidents —
typosquatting and malicious install scripts — not a generic vulnerability-database lookup.
What it catches
Typosquatting. Dependency names within 1-2 character edit distance of one of the npm registry's
most-depended-on packages (lodash, express, react, axios, and ~90 others) — the actual real targets of
typosquat campaigns, since attackers go after the packages with the largest install base. lodahs, expres,
reqeust all flag; an unrelated, genuinely distinct package name doesn't.
Malicious install scripts. preinstall/install/postinstall hooks run automatically on npm install,
before any of the package's own code is ever reviewed — the actual delivery mechanism behind real incidents
(event-stream 2018, ua-parser-js 2021, and others since). Flags scripts that pipe a remote download directly
into a shell, and scripts that decode an obfuscated base64 payload before running it.
Unpinned versions. Dependencies on * or latest pull in whatever gets published next, silently, with no
diff in your repo to explain why your dependency tree changed.
Tools
audit_package_json
Full audit of a package.json file.
check_package_name
Focused typosquat check on a single package name.
Use it
Hosted (recommended): MCPize — free tier, $7/mo Pro.
Self-host:
npm install
node server.js
Part of a small suite
secrets-leak-audit-mcp, mcp-trust-audit-mcp, github-actions-audit-mcp, dockerfile-audit-mcp.
License
MIT
Update 1.1.0 (2026-10-01)
- New tools
inspect_package_liveandaudit_dependencies_live: look packages up on the live npm registry. Flags names that do not exist (hallucinated or mistyped), brand-new low-traffic packages, install scripts, deprecated releases and typosquats.
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Worldmonitor
Freeby Koala73 · Developer Tools
Live markets, conflicts, country risk, chokepoints, energy, and China decision signals. 86 tools.
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
