Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Auto-Unpublish NPM Packages Published Outside CI

Details

External ID
46069645
Source
HN
Company
—
Product
Auto-Unpublish NPM Packages Published Outside CI
Website domain
github.com
Launched
Nov. 27, 2025
Cohort
—
Upvotes
6
Upvotes percentile
0.27074235807860264
Tags
—
Fetched at
Sept. 7, 2026, 9:25 p.m.
Updated at
Sept. 7, 2026, 9:25 p.m.

Description

A lot of vendors and open-source projects shared guidance on protecting users from downloading malicious NPM packages after the Shai-Hulud campaign — but almost nothing focused on protecting maintainers from accidentally (or maliciously) publishing them.So we built a small tool that continuously monitors your NPM packages and automatically unpublishes any version not produced by your CI workflow.

Enrichment

Theme
self-hosted infrastructure and security tools
Vertical
Horizontal
Function
Workflow automation
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
npm package publishing safeguard
Manually corrected
False

Could you build this?

Yes This is a straightforward security utility that polls the NPM registry or listens to webhooks, compares publish metadata against GitHub Actions/CI provenance, and calls the NPM unpublish API.

Discussion

2 comments analyzed.

Concerns raised: Only reactive damage control, not preventative security, Gives false sense of security if CI already compromised, Doesn't actually lock down or protect release process, NPM token should never be visible to tools anyway

Competitors

Other products that read as similar to this one — 32 launches clear the similarity bar, closest 8 shown.

Attention rank: #31 of 33 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 4 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a workflow automation tool for Real estate yet.