npm-scan
Version updated for https://github.com/lateos-ai/npm-scan to version v1.5.0.
- This action is used across all versions by 0 repositories.
Action Type
This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary
Summary:
npm-scan is a comprehensive security tool designed to detect advanced attack vectors not caught by traditional tools like npm audit, Snyk, or Socket. It focuses on identifying obfuscated payloads, credential stealers, kernel rootkits, eBPF hooks, memory extraction, GitHub spoofing, and AI-targeted attacks. The action provides 95%+ confidence in detecting these vulnerabilities and significantly reduces the risk of data breaches, regulatory fines, and financial liability.
What’s Changed
npm-scan v1.5.0
Release Summary
- Campaign Detection: 100% (3/3 real attacks)
- False Positive Rate: 0.0% (0/990 packages)
- Tests: All 671 passing
- Code Quality: 0 linting errors
Validation Metrics
- D6 (Version Anomaly): 92% avg confidence
- D7 (Obfuscation): 80% avg confidence
- D1 (Typosquat): 87.9% avg confidence
See VALIDATION.md for full metrics.
Published with npm provenance attestation (SLSA Level 2).