Malicious Package Scanner

Local · No API Cost

GuardDog-style static analysis for npm/PyPI supply-chain attacker techniques

Paste a package.json or requirements.txt. Checked for suspicious install/lifecycle scripts and dependency-name typosquats against a curated list of well-known packages — a few hundred names, not exhaustive, so a clean result is not a clean bill of health.