Supply-chain threat detection & response for npm & PyPI/Python
No confirmed malicious install- or import-time behavior. Network and filesystem capabilities are scanner functions activated by explicit CLI commands; optional LLM source submission requires a user-provided API key.
Package contains a critical-looking secret pattern.
src/integrations/canary-tokens.jsView on unpkg · L158OpenSSH private key in src/integrations/canary-tokens.js
src/integrations/canary-tokens.jsView on unpkg · L158Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
bin/muaddib.jsView on unpkg · L15Package source references dynamic require/import behavior.
bin/muaddib.jsView on unpkg · L25Source mutates package metadata and republishes itself to npm.
src/response/playbooks.jsView on unpkg · L14Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
src/rules/index.jsView on unpkg · L14A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/rules/index.jsView on unpkg · L14GitHub personal access token in src/sandbox/index.js
src/sandbox/index.jsView on unpkg · L207AWS access key ID in src/scanner/ast-detectors/anti-evasion.js
src/scanner/ast-detectors/anti-evasion.jsView on unpkg · L55Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/rules/index.jsView on unpkg · L14Source writes installer persistence such as shell profile or service configuration.
src/rules/index.jsView on unpkg · L14Package contains a critical-looking secret pattern.
src/integrations/canary-tokens.jsView on unpkg · L158OpenSSH private key in src/integrations/canary-tokens.js
src/integrations/canary-tokens.jsView on unpkg · L158GitHub personal access token in src/sandbox/index.js
src/sandbox/index.jsView on unpkg · L207AWS access key ID in src/scanner/ast-detectors/anti-evasion.js
src/scanner/ast-detectors/anti-evasion.jsView on unpkg · L55Package source references dynamic require/import behavior.
bin/muaddib.jsView on unpkg · L25Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
bin/muaddib.jsView on unpkg · L15Source mutates package metadata and republishes itself to npm.
src/response/playbooks.jsView on unpkg · L14Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/rules/index.jsView on unpkg · L14Source writes installer persistence such as shell profile or service configuration.
src/rules/index.jsView on unpkg · L14Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
src/rules/index.jsView on unpkg · L14A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/rules/index.jsView on unpkg · L14