Install Safe
  • Blog
  • How it works
  • Pricing
  • Free scanner
6 Malicious npm Packages: Check Exposure Now
npm security

6 Malicious npm Packages: Check Exposure Now

Six newly disclosed malicious npm packages can steal secrets or execute remote code. Check versions and investigate affected systems.
Read more
Prasanna Mestha
bx-ui-framework Authentication Malicious Package Alert
npm security

bx-ui-framework Authentication Malicious Package Alert

MAL-2026-15866 flags all published versions of @bx-ui-framework/authentication as malicious. Check exposure, remove it, and investigate installs.
Read more
Prasanna Mestha
Malicious npm Packages: Detection and Response Guide
npm security

Malicious npm Packages: Detection and Response Guide

A field guide to how malicious npm packages spread, how to detect them before install, and how to contain exposure safely.
Read more
Prasanna Mestha
npm Registry Firewall: How It Blocks Bad Packages
npm security

npm Registry Firewall: How It Blocks Bad Packages

A practical guide to how registry firewalls intercept npm package requests, enforce policy, and complement SCA and behavioral analysis.
Read more
Prasanna Mestha
6 Malicious npm Packages Disclosed September 4
npm security

6 Malicious npm Packages Disclosed September 4

Six malicious npm packages were disclosed September 4. Check your lockfiles, contain affected hosts, and rotate potentially exposed credentials.
Read more
Prasanna Mestha
CodeCatalyst Blueprints Command Injection: Upgrade Now
npm security

CodeCatalyst Blueprints Command Injection: Upgrade Now

CVE-2026-85012 lets a repository contributor inject OS commands during blueprint resynthesis. Check for affected versions and upgrade.
Read more
Prasanna Mestha
Quantix Finance npm Malware: 10 Packages Steal Secrets - all you need to know
npm security

Quantix Finance npm Malware: 10 Packages Steal Secrets - all you need to know

Ten malicious @quantixfinance packages harvest environment credentials and wallet secrets during npm preinstall. Here is how to check and respond.
Read more
Prasanna Mestha
Stellarshift and Tailwind npm Malware Alert
npm security

Stellarshift and Tailwind npm Malware Alert

Six malicious npm packages use targeted install hooks, host-data exfiltration, and a self-erasing blockchain-C2 loader. Check exposure and respond safely.
Read more
Prasanna Mestha
Orval npm RCE Advisories: Upgrade to 8.22.0
npm security

Orval npm RCE Advisories: Upgrade to 8.22.0

Three Orval advisories enable import-time RCE, SSRF, and file inclusion. Check exposure and upgrade the npm package to 8.22.0 or later.
Read more
Prasanna Mestha
eslint-rxjs 1.0.1 Is Malicious: Check Exposure
npm security

eslint-rxjs 1.0.1 Is Malicious: Check Exposure

OpenSSF flagged eslint-rxjs 1.0.1 as malicious. Check lockfiles and CI logs, remove it, and investigate the affected environment.
Read more
Prasanna Mestha
FOSSA Alternative for npm Supply-Chain Security (2026)
npm security

FOSSA Alternative for npm Supply-Chain Security (2026)

FOSSA is built for license compliance, not blocking malicious npm packages. Compare the best FOSSA alternatives for npm supply-chain security in 2026.
Read more
Prasanna Mestha
How to Check if an npm Package Is Safe (2026 Guide)
npm-security

How to Check if an npm Package Is Safe (2026 Guide)

Seven checks to run before installing any npm package, the red flags of malicious code, and how to automate protection for the dependencies you can't vet by hand.
Read more
Prasanna Mestha
Install Safe © 2026
  • Scan your project
  • installsafe.io
Powered by Ghost