# Install anti-trojan-source with npm

Detect trojan source attacks that employ unicode bidi attacks to inject malicious code. Version 1.12.1 via npm; verified 2026-07-23.

## Install

```sh
sudo av install npm:anti-trojan-source
```

Additional install commands:

### Portable and language managers

- npm (100%):

```sh
npm install -g anti-trojan-source
```

  Evidence: local npm package metadata

## Package facts

- **Package key:** npm:anti-trojan-source
- **Package manager:** npm
- **Package manager page:** <https://www.npmjs.com/package/anti-trojan-source>
- **Version:** 1.12.1
- **Source summary:** Detect trojan source attacks that employ unicode bidi attacks to inject malicious code
- **Homepage:** <https://github.com/lirantal/anti-trojan-source>
- **Repository:** <https://github.com/lirantal/anti-trojan-source>
- **Upstream docs:** <https://github.com/lirantal/anti-trojan-source>
- **License:** Apache-2.0
- **Source archive:** <https://registry.npmjs.org/anti-trojan-source/-/anti-trojan-source-1.12.1.tgz>
- **Issue tracker:** <https://github.com/lirantal/anti-trojan-source/issues>
- **Published:** 2026-07-23T18:57:57.222Z
- **Last updated:** 2026-07-23T18:57:57.222Z
- **Generated:** 2026-08-04T22:13:35+00:00

## Executables

- anti-trojan-source (cli)
- anti-trojan-source (alias)

## Dependencies

- globby
- meow

## Build dependencies

- @babel/core
- @babel/eslint-parser
- @babel/plugin-syntax-top-level-await
- @commitlint/cli
- @commitlint/config-conventional
- @semantic-release/changelog
- @semantic-release/commit-analyzer
- @semantic-release/git
- @semantic-release/github
- @semantic-release/npm
- @semantic-release/release-notes-generator
- eslint
- eslint-plugin-jest
- eslint-plugin-node
- eslint-plugin-security
- eslint-plugin-standard
- husky
- jest
- lint-staged
- lockfile-lint
- open-cli
- prettier
- rollup
- semantic-release

## Install behavior

- Post-install hook: not defined
- Bottle: not available

## Freshness

- Page generated: 2026-08-04
- Package-manager version: 1.12.1
- Package-manager updated: 2026-07-23
- Local data: ok
- Upstream repository: https://github.com/lirantal/anti-trojan-source
- info: No cached GitHub release or tag data was available.

## Security Notes

No matching local secret-handling manifest was found for anti-trojan-source. Package metadata is still published here so future coverage has a stable package URL.


## Source Database Details

- **Source Database:** npm registry
- **Dist Tags:** Latest: 1.12.1
- **Version Count:** 32
- **Maintainers:** lirantal, lirantal_bot
- **Author:** Liran Tal
- **Publisher:** GitHub Actions
- **Engines:** Node: >=24.0.0, npm: >=11.10.0
- **Integrity:** sha512-GHzx0oxetdx0RHDxzU3nRYAYRo7xiZRwHjutFxVOsq6kOD/ARyc50wK0MMBWys/E3KIvaMNY4SzKElTrVmIvew==
- **Shasum:** e771179d12e5f27e97cabf8898bded936869e646
- **Unpacked Size:** 96,841
- **File Count:** 0
- **Created At:** 2021-11-05T14:38:37.755Z
- **Latest Published At:** 2026-07-23T18:57:57.222Z
- **Modified At:** 2026-07-23T18:57:57.736Z


## Related links

- [Security and crypto packages](https://pkg.so/security-crypto-tools/) - Matched curated package taxonomy and local package facts.
- [auditjs](https://pkg.so/npm/auditjs/) - Security-sensitive metadata or terminology overlaps. Shared terms: cli, http, npm, scanning, security.
- [better-npm-audit](https://pkg.so/npm/better-npm-audit/) - Security-sensitive metadata or terminology overlaps. Shared terms: cli, http, npm, scanning, security.
- [audit-ci](https://pkg.so/npm/audit-ci/) - Security-sensitive metadata or terminology overlaps. Shared terms: cli, http, npm, scanning, security.

## Sources

- pkg.so package database
- package-page enrichment
- package version freshness
- pkgdb category and tag curation
- package relationship graph
- cross-ecosystem install command graph
