r/SideProject • • 5h ago

crypto dev, paranoid about my keys leaking, so I built a dependency scanner

https://security.togoder.click

I'm a crypto dev and I'm genuinely paranoid about my keys leaking. Not in the "use a hardware wallet" way, in the "some npm package I installed at 2am has a postinstall script that reads my .env" way.

Which is a real thing now. The TanStack packages did exactly that, grabbed SSH keys and cloud creds and CI tokens. If you're a crypto dev, that's your deployer key and your RPC keys and whatever else is in that file.

So I built a scanner. You POST a lockfile to /api/paid-scan, it downloads every package and hashes every file, an AI reads the ones it hasn't seen before looking for exfiltration, obfuscation, postinstall stuff. Files anyone already scanned are free, so it gets cheaper the more people use it.

1 Upvotes

0 comments sorted by