
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
pkgscan
is a useful tool to inspect installed packages in your project. It provides detailed information about installed packages managed by popular package managers like npm
, pnpm
and yarn
.
If you find this package useful for your projects, please consider supporting me by Patreon, KO-FI or Paypal. It's a great way to help me maintain and improve this tool in the future. Your support is truly appreciated!
npm
# Try with npx
npx pkgscan [options]
# Locally in your project.
npm install pkgscan
# Or globally (use as cli)
npm install -g pkgscan
pkgscan [options]
Options:
-p, --pkg The name of the package to retrieve information for.
-c, --cwd The current working directory of the project.
-h, --help Show help
# Get details about the installed package with automatic package manager detection.
pkgscan --pkg typescript
# Get details about the installed package with glob pattern.
pkgscan --pkg '@types/*'
# To scan all installed packages
pkgscan --pkg '*'
# Get details about the installed package with a user-specified package manager.
pkgscan --pkg typescript --cwd ./project-directory-path
import { getInstalledPackage } from 'pkgscan';
// Get details about the installed package with automatic package manager detection.
const installedPackage = getInstalledPackage('typescript');
console.log(installedPackage);
/*
[
{
name: 'typescript',
version: '5.1.3',
isDirectProjectDependency: true,
dev: true,
license: 'Apache-2.0',
engines: { node: '>=14.17' }
}
]
*/
// Get details about the installed package with a user-specified package manager.
const cwd = __dirname;
const installedPackage = getInstalledPackage('typescript', cwd);
console.log(installedPackage);
/*
[
{
name: 'typescript',
version: '5.1.3',
isDirectProjectDependency: true,
dev: true,
license: 'Apache-2.0',
engines: { node: '>=14.17' }
}
]
*/
isDirectProjectDependency
used to determine whether a package is a direct dependency of a project or not. By using this variable, you can check whether a package is directly listed in the dependencies section of the project's package.json file or not.
If you discover a bug, or have a suggestion for a feature request, please submit an issue.
This extension is licensed under the MIT License
1.0.25
FAQs
Retrieve information on installed packages across npm, pnpm and yarn
The npm package pkgscan receives a total of 457 weekly downloads. As such, pkgscan popularity was classified as not popular.
We found that pkgscan demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.