Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
np-audit — Static security analysis for npm packages. Detects obfuscated code, malicious patterns, and known vulnerabilities before installation. | Kitploit
Tools/GitHubGitHub/koblers/np-audit
Static AnalysisVulnerability ScannersCode AnalysisMalware AnalysisSecret DetectionSupply Chain Security
GitHubkoblers/np-audit

np-audit

Static security analysis for npm packages. Detects obfuscated code, malicious patterns, and known vulnerabilities before installation.

View Repository
72112h 22m agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

np-audit

npm version npm downloads npm package size GitHub license CI codecov

np-audit — npm package auditor

Static security analysis for npm packages — detects obfuscated lifecycle scripts, known vulnerabilities, and malicious patterns before they run. Drop-in replacement for npm install and npm ci.

Zero dependencies. Pure Node.js built-ins only. < 100 kB on the wire.

npx np-audit scan express
npm install -g np-audit
npa scan                     # scan all deps
npa install                  # audit then install
alias npm='npa'              # use as drop-in replacement

Marshallers

Detection is split into modular marshallers — each one detects a single attack signal:

MarshallerWhat it detectsScore
eval/dynamic-execeval(), new Function(), indirect eval, vm.*, setTimeout with string8
obfuscator.io_0x variable naming patterns (obfuscator.io output)9–80
high-entropy-stringLong strings or concatenation chains with high Shannon entropy6
hex-escape-densityDense \xNN and \uXXXX escape sequences5–50
fromCharCodeString.fromCharCode with many args, large decimal char-code arrays7
encoded-decodeBase64/hex decode (atob, Buffer.from) optionally combined with eval3–8
child-processrequire('child_process'), exec, spawn, fork, worker_threads5
hex-arrayLarge numbers of 0x hex literal values7–60
process-envprocess.env access (credential exfiltration signal)3
network-callrequire('https'), fetch(), dns, net, tls4
filesystem-manipulationfs.writeFile, chmod, symlink (backdoor persistence)3–4
runtime-downloadDownloads and executes external runtimes (Bun, Deno)9–50
vscode-autorunVS Code tasks with runOn: folderOpen (auto-execution)30
known-vulnerabilityKnown CVEs via Snyk API or OSV.dev4–6 (WARN), 80 (malicious)

Scores scale with severity — higher counts of obfuscation indicators produce higher scores. The final verdict is based on the highest individual score across all marshallers.

See CONTRIBUTING.md for how to write custom marshallers.


Vulnerability Scanning (CVE)

Every scanned package is checked against known vulnerability databases alongside the code analysis.

Default: OSV.dev (no setup required)

Works out of the box — queries the free OSV.dev API for known vulnerabilities and malicious package advisories.

Optional: Snyk API (richer data)

# Environment variable
export SNYK_API_TOKEN=your-token-here

# Or via Snyk CLI
snyk auth

Token resolution order: SNYK_API_TOKEN → SNYK_TOKEN → ~/.config/configstore/snyk.json

SeverityScoreVerdict
Malicious package80DANGER
10+ vulnerabilities6WARN
5–9 vulnerabilities5WARN
1–4 vulnerabilities4WARN

Non-malicious CVEs produce warnings but never block installation. Only confirmed malicious packages trigger DANGER.


Usage

Commands

CommandAliasDescription
npa install [package]npa iAudit then run npm install
npa ci—Audit then run npm ci
npa scan [package]npa sScan only, no install
npa config getnpa c getShow current configuration
npa config set <key> <value>npa c setUpdate a config value
npa alias --install—Install shell alias
npa alias --uninstall—Remove shell alias

Any unrecognized command is forwarded to npm (e.g. npa run test, npa publish).

Flags

FlagAliasWorks withDescription
--review-rinstall, ciInteractive mode — choose which scripts to allow
--json—install, ci, scanMachine-readable JSON output
--no-dev—install, ci, scanSkip devDependencies
--verbose—allShow fetch progress and extra detail
--version-v—Print version and exit
--help-h—Print help and exit

Interactive --review mode

npa install --review
  npa --review mode
  Use ↑/↓ to navigate, SPACE to toggle, ENTER to confirm, q to quit

  Found 3 package(s) with install scripts:

     [✓ allow] [email protected]       postinstall: post-install.js     OK
   ▶ [✗ deny ] [email protected]       postinstall: install.js          DANGER (score: 9)
     [✓ allow] @scope/[email protected]     postinstall: install.js          WARN (score: 5)

  2 allowed  1 denied

Configuration

Config is stored in ~/.npmauditor.json (global) and can be overridden per project with .npmauditor.json.

npa config get                              # Show current config
npa config set blockScore 6                 # Block at score 6+
npa config set skipPackages '["esbuild"]'   # Trust specific packages
npa config set skipScopes '["@types"]'      # Trust entire scopes

All config keys

Download Tool