Show HN: DepWarden β free, anonymous dependency vulnerability scannerhttps://depwarden.in/blog/npm-pypi-typosquatting-2026-report
No account, no source upload β paste a manifest/lockfile and get OSV+KEV+EPSS-prioritized findings in a session-isolated workspace. Also ran a typosquat study: checked every single-char typo of the 30 most popular npm/PyPI packages against the real registries and OSV's malicious-package DB β 32.7% of registered npm look-alikes are already confirmed malicious. Data/methodology: https://depwarden.in/blog/npm-pypi-typosquatting-2026-report Comments URL: https://news.ycombinator.com/item?id=49596333 Points: 1 # Comments: 0
