Skip to content

Interest: maintainer-change-check as a complementary signal (npm), distinct from typosquat detection itself #539

Description

@presendapp

Disclosure: I'm the developer of Presend (https://presend.pages.dev), flagging that upfront -- this is a self-interested suggestion.

Not proposing typosquat detection -- that's your core focus and top_npm_reference.py/trusted_packages already look like a solid, purpose-built approach. What might be a genuine complement: Presend's maintainer-change-check flags an npm publisher change after a long dormancy period -- the event-stream pattern. Different attack vector (a legitimate-looking, correctly-named package changing hands) than typosquatting, so not overlapping. npm-only currently, free, no key.

Also noticed twyn/mcp/main.py -- if there's ever a place for cross-referencing complementary MCP tools, Presend also runs one (36 tools) published to the official registry.

I don't have visibility into your dependency_managers/trusted_packages architecture, so I don't want to guess at Python that might not match. Happy to look at the real structure and put together a properly-formatted addition if this is a direction you'd want.

Docs: https://presend.pages.dev/api#GET-api-maintainer-change-check


Edit (2026-09-25): corrected an inaccurate claim above. maintainer-change-check matches the event-stream pattern (a previously unseen publisher taking over after long dormancy). It does not detect a hijacked existing account (ua-parser-js) or a malicious release by an existing maintainer (colors.js), and it is npm-only. It now also only flags recent takeovers (last 365 days), after testing showed false positives on years-old legitimate handoffs.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions