A security researcher has released a new tool designed to help developers check npm packages impacted by the recently discovered manifest confusion issue in the registry. System administration and self-confessed hacker, Felix Pankratz, published the tool to GitHub on Monday, claiming the Python script can check npm packages for manifest mismatches, and also check all package dependencies recursively.
Source: Infosecurity