Typosquat and quality signals for an npm package before installing it: weekly downloads, latest version, license, deprec
Typosquat and quality signals for an npm package before installing it: weekly downloads, latest version, license, deprecation notice, repository link, and computed risk flags (low_downloads, deprecated, no_repository, no_license, not_found). A package with 12 weekly downloads pretending to be a popular library is the classic supply-chain attack on coding agents. Pairs with the package-vulns endpoint for CVE checks.
https://relay402.georgespring.workers.dev/api/npm-package-check ↗Statuscataloged
Networkeip155:8453
Schemeexact
First seen2026-08-30T16:44:47Z
Payment + protocol
Method
GETProtocol
x402 v2Network
eip155:8453Scheme
exactAsset
0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913Amount
10000Pay to
0x73fc43d426a89577c7b58f5fee50ec95d4396079Evidence
bazaarFirst seen
2026-08-30T16:44:47ZLast seen
2026-08-30T20:17:50Z