Find Any npm Username with WhatsMyName App
npm is the largest software registry in the world, and the maintainer handle behind a package is a supply chain security question, not a trivia one. WhatsMyName App checks whether an npm profile exists at a handle alongside 731 other platforms in one search.
Platform: Developer, package registry · The largest software registry in the world
Search npm Username FreeWhat Is npm and Why Username Searches Matter
npm is the package registry for the JavaScript ecosystem, hosting millions of packages that are installed billions of times a week. Every publisher has a profile at npmjs.com/~username listing the packages they maintain, which makes maintainer identity directly checkable by anyone.
That check has become genuinely important. Through 2026 a series of maintainer account takeovers hit widely used packages: the Axios compromise in March 2026 reached a package with over 50 million weekly downloads, the Mastra ecosystem was poisoned through a maintainer account with publish rights, and the maintainers of debug, chalk and ansi-styles were phished with a proxy that intercepted their multi factor tokens. In each case the attack path was the human account, not the code.
So people check npm handles for concrete reasons. Security teams verify that the maintainer of a dependency has a consistent, long standing identity across GitHub and elsewhere. Developers evaluating an unfamiliar package check whether the publisher exists anywhere else, since a brand new handle with no footprint is a typosquatting signal. Maintainers audit their own exposure, because a public handle is the starting point for a phishing campaign aimed at them.
How npm Usernames Work
npm usernames are lowercase, unique, and allow letters, numbers, hyphens and underscores. The profile lives at npmjs.com/~username, with the tilde being the part people most often get wrong when constructing the URL by hand.
Scoped packages introduce a second kind of name. A scope like @scopename can belong to a user or an organisation, so the publisher shown on a package page is not always an individual handle. When you are verifying a maintainer, check the profile behind the scope rather than assuming the scope is a person.
Handle reuse between npm and GitHub is very high, because packages are usually published from a repository. That pairing is the core verification: an npm handle with a matching GitHub account, and a package whose repository link points at that same account, is coherent. A mismatch between the three is worth investigating before you install anything.
- Usernames are lowercase and unique
- Profile URL format: npmjs.com/~username, with a tilde
- Scopes like @name may be an organisation rather than a person
- Very high handle overlap with GitHub
- Package repository links should match the maintainer handle
How to Search an npm Username with WhatsMyName App
No account, no install, no cost. Results in under 90 seconds.
Go to WhatsMyName App
Open whatsmynameapp.us in any browser. No account required, nothing to install.
Enter the npm handle
Type the maintainer username without the tilde. Take it from the package page's maintainer list rather than guessing.
Run the search
Click Search. All 732 platforms are checked in parallel, including npm.
Find the npm result
Results stream in as each check completes. Look for the npm entry showing confirmed or not found.
Click through to verify
Open a confirmed result to see the packages the account maintains and how long it has been publishing.
Compare against GitHub
Check the GitHub and GitLab results from the same scan, and confirm the package's repository link points to the same account rather than an unrelated one.
Export the results
When the scan finishes, export every found account to CSV, which is useful evidence to attach to a dependency review.
What WhatsMyName App Shows for npm
A confirmed npm result links to the maintainer profile and the packages it publishes. For a dependency review, the useful signals are how long the account has existed, how many packages it maintains and whether those packages have real download histories rather than a single recent publish.
A not-found result on npm alongside a package that lists the handle usually means a mistyped username, since scopes and hyphens are easy to get wrong. A handle that resolves on npm but nowhere else in the scan is the pattern worth pausing on: a publisher with no GitHub presence and no history anywhere is exactly what a typosquatting or throwaway account looks like.
Ready to check an npm username?
Open WhatsMyName AppAfter Finding an npm Account
For a dependency review, do the three way check. The npm maintainer handle, the GitHub account under the same handle, and the repository link on the package page should all agree. The 2026 takeovers succeeded through compromised accounts rather than forged identities, so also weigh how recently a long standing package changed maintainers or publishing patterns.
For maintainers auditing themselves, a public handle is an attack surface. Every platform the same handle appears on is a potential phishing route, and the phishing that hit debug and chalk used a real time proxy that defeated normal multi factor codes. Knowing your full handle footprint tells you where an attacker will aim.
If a handle exists only on npm with no footprint elsewhere, treat unfamiliar packages from it with more care: check the download history, read the published files, and prefer packages whose maintainer identity you can corroborate.
- Match npm handle, GitHub account and repository link
- Watch for maintainer or publishing pattern changes on old packages
- A handle with no footprint elsewhere is a typosquatting signal
- Maintainers: your handle footprint is your phishing surface
Related Platform Searches
WhatsMyName App checks these platforms alongside npm in a single search. Explore the guides below or browse all OSINT tools available on this site.
Packages are normally published from a GitHub repository, so a matching GitHub account is the single most important corroboration of a maintainer identity.
Some maintainers host outside GitHub, so checking GitLab avoids wrongly concluding a publisher has no code presence.
Long standing maintainers usually have a public answer history under the same handle, which adds age and consistency to an identity.
People who reuse a handle on npm tend to reuse it on these too:
Every platform guide on this site is listed on the WhatsMyName App guide.
Frequently Asked Questions about npm Username Search
How do I check who maintains an npm package?
Take the maintainer handle from the package page, then search it in WhatsMyName App. The npm result confirms the profile at npmjs.com/~handle exists, and the rest of the scan shows where else that handle appears.
Why does maintainer identity matter for security?
Because the account is the attack path. Through 2026, Axios, the Mastra ecosystem and the debug and chalk packages were all compromised through maintainer account takeovers and phishing rather than through flaws in the code itself.
What does it mean if the handle exists only on npm?
It is a caution signal, not proof of anything. A publisher with no GitHub, GitLab or other presence has no history you can verify, which is the pattern typosquatting and throwaway accounts follow.
What is the correct npm profile URL?
npmjs.com/~username, with a tilde before the handle. Leaving out the tilde is the most common reason a manually constructed npm profile URL fails.
Is a scoped package the same as a user?
Not necessarily. A scope like @name can belong to an organisation rather than an individual, so check the profile behind the scope instead of assuming it is a person.
Is checking an npm maintainer handle legal?
I maintain packages, how does this help me?
It shows you your own handle footprint, which is what an attacker enumerates before a phishing attempt. The 2026 phishing against popular package maintainers used a proxy that captured multi factor tokens, so knowing where your handle is exposed is a practical defensive step.
Search Any npm Username Now
WhatsMyName App checks npm and 731 other platforms simultaneously. Free, no sign-up, results in under 90 seconds. Read the full WhatsMyName App guide to get the most out of every search.
Run an npm Username Search