NpmJaagratha
Node.js security, built with jaagratha.
Security monitoring for npm

Every commit. Every push. Every dependency change.

Automatically scan your Node.js projects for vulnerabilities, malware packages, leaked secrets, and supply chain attacks. Paste package.json to get an instant risk summary without login.

You ship code. We make sure itโ€™s clean.

No login required

Different tools solve different security problems. NpmJaagratha focuses on malware-like behavior, drainers, obfuscation, sketchy scripts, and supply-chain risks, not just known CVEs.

No install, no login, no API keys
Paste package.json, get instant risk summary
Built to catch drainers & supply-chain attacks
Coverage
Dependencies, secrets, PRs
Latency
Scans in seconds
Tone
Clear, calm, and actionable
npmjaagratha scan --live
Live dependency sweep

[scan] repo connected from GitHub App

[scan] package-lock parsed, 42 dependencies mapped

[alert] 1 suspicious install script isolated

[alert] exposed token signature matched entropy rule

[result] risk score adjusted to 73/100

Risk scoreDanger
73
/100
Vulnerable packages
4
Safe packages
38
Malware hits
1
Secrets exposed
2
PR checks passed
17
Trusted Security Monitoring

Built for developers who want a fast, no-login risk check.

A premium security layer for npm projects, tuned for developers who want strong signals without noise and a clean paste-in workflow.

Vulnerability Scanning

Track known CVEs across every dependency update.

Signal 1

Secret Detection

Catch exposed API keys, tokens, and env leaks early.

Signal 2

Supply Chain Protection

Spot compromised packages and risky maintainer paths.

Signal 3

Malware Package Detection

Flag suspicious install scripts and malicious payloads.

Signal 4

Dependency Risk Scoring

Rank packages by trust signals and exploitability.

Signal 5

GitHub PR Security Checks

Comment on pull requests with precise remediation.

Signal 6
How It Works

A clean flow from pasted package.json to instant protection.

The flow stays simple. The signal stays strong. Your team gets security context where it matters most.

01

Paste package.json

Drop in a package.json file or snippet and start the scan instantly.

02

Push code

Every push, PR, and lockfile change becomes a security checkpoint.

03

Automatic scans run

NpmJaagratha checks dependencies, scripts, and secrets in real time.

04

Get instant alerts and fixes

Receive actionable comments, dashboards, and risk scores.

Security Features

Deep checks for every package move.

package.json scanning
package-lock.json analysis
npm malware detection
typo-squatting detection
suspicious install scripts
exposed API key detection
maintainer trust analysis
dependency graph visualization
PR comments and GitHub checks
Live Scan Preview

Risk moves with every commit.

Active scan
Recent alerts
โš ๏ธ Jaagratha! Risky dependency detected.
event-stream-like behavior flagged in the latest tree update.
๐Ÿ›‘ Visham detected in package tree.
A newly introduced package has an unusual install script and low trust signals.
๐Ÿ” Package sookshikkanam.
Lockfile diff reviewed. No secret leaks and no suspicious postinstall scripts.
Scan timeline
package.json diff
lockfile review
secret sweep
Live Feed

LATEST NPM VULNERABILITIES

Real-time feed of reviewed security advisories affecting the npm ecosystem, sourced from the GitHub Advisory Database.

Malayalam Alerts

Subtle cultural touch. Premium security tone.

โš ๏ธ Jaagratha! Risky dependency detected.

event-stream-like behavior flagged in the latest tree update.

๐Ÿ›‘ Visham detected in package tree.

A newly introduced package has an unusual install script and low trust signals.

๐Ÿ” Package sookshikkanam.

Lockfile diff reviewed. No secret leaks and no suspicious postinstall scripts.

Get Started

Paste a package.json and get a risk summary in seconds.

No install, no login, no API keys. Start with a package.json snippet or file, and NpmJaagratha flags vulnerable dependencies, drainers, suspicious scripts, and supply-chain attacks immediately.