worm-sign

worm-sign JS library on GitHub worm-sign JS library on npm Download worm-sign JS library

A security scanner that detects npm packages compromised by supply chain attacks, including the TanStack wave 4 attack (May 2026), the Axios attack (March 2026), and Shai-Hulud malware.

Version 4.2.0 License MIT
worm-sign has no homepage
worm-sign JS library on GitHub
worm-sign JS library on npm
Download worm-sign JS library
Keywords
securityscannermalwareshai-huludwormvulnerabilitiesnpmyarnpnpmsupply-chaindevsecopsauditlockfileintegrityanalysis