Three packages in a typical project are CRITICAL right now: chalk (399M downloads/week, 1 maintainer), zod (139M, 1 maintainer), axios (96M, 1 maintainer — attacked April 1st). Stars and READMEs don't show this. Behavioral signals do.
| Package | Score | Risk | Maintainers | Weekly DL | Age | Trend |
|---|
Want this in your AI assistant?
{
"mcpServers": {
"commit": {
"type": "streamable-http",
"url": "https://poc-backend.amdal-dev.workers.dev/mcp"
}
}
} Add to Claude Desktop, Cursor, or any MCP client. Then: "Audit my package.json for supply chain risk"
Scoring packages…
Risk flags: CRITICAL = single maintainer + >10M weekly downloads (exact LiteLLM/axios attack profile). HIGH = package <1yr old + rapid adoption. WARN = no release in 12+ months.