npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@meowrypto/depguard

v0.2.0

Published

Scan installed npm dependencies for crypto-stealer style behavior (clipboard hijacking, seed-phrase hunting, exfiltration, obfuscated payloads) before you trust them.

Readme

DepGuard

npm version npm downloads CI License: MIT

Scan your installed npm dependencies for crypto-stealer style behavior — clipboard hijacking, seed-phrase hunting, exfiltration to Discord/Telegram/Pastebin, obfuscated payloads, and postinstall scripts that fetch-and-run — before you trust them.

Supply-chain attacks that target crypto wallets are a real and growing threat: a compromised or typosquatted npm package doesn't need to be sophisticated, it just needs to read your clipboard or your .env file once. DepGuard is a small, dependency-free heuristic scanner you can run locally or in CI to catch the most common patterns those attacks share.

DepGuard is a heuristic tool, not a guarantee. A finding means "this deserves a human look," not "this is malware." It will have false positives (a legitimate crypto library will trip the seed-phrase pattern) and it can be evaded by a determined attacker. Use it as one more check, not your only one.

Install

No install needed — run it directly:

npx @meowrypto/depguard

Or install as a dev dependency:

npm install --save-dev @meowrypto/depguard

Usage

# Scan node_modules in the current directory (default)
npx @meowrypto/depguard

# Scan a specific directory
npx @meowrypto/depguard ./some-folder

# Only fail (exit code 1) on medium severity or above — useful for stricter CI
npx @meowrypto/depguard node_modules --fail-on medium

# Output machine-readable JSON
npx @meowrypto/depguard node_modules --json > report.json

Exit code is 0 when nothing at or above the --fail-on threshold (default: high) is found, and 1 otherwise — so it plugs straight into CI.

What it looks for

| Category | Examples | |---|---| | Clipboard access | reading/writing the clipboard (classic wallet-address swap attack) | | Seed phrase / key hunting | BIP39 wordlist references, wallet.dat, privateKey = | | Exfiltration channels | Discord webhooks, Telegram Bot API, Pastebin, raw IP requests | | Obfuscation | eval(), new Function(), base64-decode-then-execute | | Install-time execution | postinstall/preinstall scripts that curl/wget and run something | | Credential harvesting | bulk process.env reads |

See lib/patterns.js for the full, commented list — every pattern includes a one-line explanation of why it's flagged.

Using it in CI

Copy examples/depguard-action.yml into your repo at .github/workflows/depguard.yml to scan your dependencies on every PR and push to main.

Why this exists

Most supply-chain security tools are built for large teams and paid tiers. DepGuard is meant to be the thing a solo developer or a small open-source crypto project can drop in for free in under a minute, with zero configuration and zero dependencies of its own.

Contributing

Pattern suggestions are very welcome — if you've seen a real attack use a technique not covered here, please open an issue or PR with a (sanitized, non-functional) example. See lib/patterns.js for the pattern format.

License

MIT — see LICENSE.