npm package intelligence

chalk — deep security report

ShadowCanopy's full breakdown of chalk on npm: verdict, AI analysis, dependency chain, network behavior, prebuilds, and obfuscated code.

Dangerous — known malicious
This package matches a known-malicious advisory and is blocked by ShadowCanopy by default.
Scanned 8/7/2026
Known maliciouschalk@6.0.0View on registry ↗latest: 6.0.0

This package matches a known-malicious advisory and is blocked by ShadowCanopy by default across every project. 1 flagged version.

Chalk 6.0.0 is the well-known legitimate terminal-coloring package; zero static findings, standard file list, and clean sandbox install with no evidence of malice.

Protect your projects free

AI breakdown

Plain-English summary of what this package does and how it behaves.

Chalk is an npm package for terminal string styling. It provides functions to apply colors and formatting to console output via included vendor modules for ANSI styles and color support detection.

Capabilities

  • Exports terminal styling functions
  • Includes ANSI styles and color support detection
  • Runs test and benchmark scripts

Data access

  • None observed

Network

  • No network access observed

Standard utility library with empty dependencies and no postinstall or network scripts; no risky behaviors evidenced in manifest or files.

Package metadata

LicenseMIT

Terminal string styling done right

Repository ↗

Files in package (24)

licensepackage/licensesource/vendor/supports-color/browser.jspackage/source/vendor/supports-color/browser.jssource/index.jspackage/source/index.jssource/vendor/ansi-styles/index.jspackage/source/vendor/ansi-styles/index.jssource/vendor/supports-color/index.jspackage/source/vendor/supports-color/index.jssource/utilities.jspackage/source/utilities.jspackage.jsonpackage/package.jsonreadme.mdpackage/readme.mdsource/vendor/supports-color/browser.d.tspackage/source/vendor/supports-color/browser.d.tssource/index.d.tspackage/source/index.d.tssource/vendor/ansi-styles/index.d.tspackage/source/vendor/ansi-styles/index.d.tssource/vendor/supports-color/index.d.tspackage/source/vendor/supports-color/index.d.ts

How ShadowCanopy checks npm packages

ShadowCanopy blocks every dependency by default and only lets through what it can verify — against live malicious-package advisories, an AI behavior scan, and a byte-for-byte hash check. It protects installs across npm, PyPI, crates.io, pkg.go.dev, RubyGems, Maven Central, NuGet, Packagist, Hex, pub.dev, Swift Package Manager.

Protect your projects freeSee what's being blocked

This report reflects ShadowCanopy's threat intelligence at page load and is informational, not a warranty. Canonical URL: https://shadowcanopy.dev/packages/npm/chalk