grishmadev/malfilter

A security script to detect potential malware packages

TypeScript

0

46 commits

updated Sep 30, 2026

See the code

See what people are saying

SourceMessageScoreDate

GitHub - grishmadev/malfilter: A security script to detect potential malware packages (r/javascript)

Hey everyone, I built an open-source security script that checks npm packages for any suspicion before installing them. It's basic and for now catches similar names of popular packages, if a package has 23 weekly downloads or a 2 hour old package. Catches similar names, 0 downloads, or 2-hour-old…

1

Sep 30, 2026

README

Malfilter

malfilter_demo.webm

Malfilter is a small security script in the form of CLI to search and determine if packages are safe to install.

Installation

  • NPM Registry
npm i malfilter@latest
# or globally by npm i -g malfilter@latest
  • From Source
npm i -g https://github.com/grishmadev/malfilter

Usage

npx malfilter -r 30 -i <pkg name>
# or malfilter -r 30 -i <pkg name> if installed globally

Features

  • Detection for Typosquatting
  • Package age based Verification
  • Popularity based Verification

Dynamically changes threshold based on popularity, package age and name similarity(Levenshtein Distance) with other packages.

Flags

  • --help: Show available flags like below
  • --install/-i: Install Package after determining if it's safe
  • --range <range>/-r <range>: Determine the size of the search limit to increase discovery (Consumes more data).

grishmadev/malfilter

A security script to detect potential malware packages

TypeScript

0

46 commits

updated Sep 30, 2026

See the code

See what people are saying

SourceMessageScoreDate

GitHub - grishmadev/malfilter: A security script to detect potential malware packages (r/javascript)

Hey everyone, I built an open-source security script that checks npm packages for any suspicion before installing them. It's basic and for now catches similar names of popular packages, if a package has 23 weekly downloads or a 2 hour old package. Catches similar names, 0 downloads, or 2-hour-old…

1

Sep 30, 2026

README

Malfilter

malfilter_demo.webm

Malfilter is a small security script in the form of CLI to search and determine if packages are safe to install.

Installation

  • NPM Registry
npm i malfilter@latest
# or globally by npm i -g malfilter@latest
  • From Source
npm i -g https://github.com/grishmadev/malfilter

Usage

npx malfilter -r 30 -i <pkg name>
# or malfilter -r 30 -i <pkg name> if installed globally

Features

  • Detection for Typosquatting
  • Package age based Verification
  • Popularity based Verification

Dynamically changes threshold based on popularity, package age and name similarity(Levenshtein Distance) with other packages.

Flags

  • --help: Show available flags like below
  • --install/-i: Install Package after determining if it's safe
  • --range <range>/-r <range>: Determine the size of the search limit to increase discovery (Consumes more data).

Languages

TypeScript

100.0%