tokens&
For enterprises
tokens&

Find tools, check provider offers, save a build plan, and share your work when you’re ready.

For buildersFor enterprises

For builders

  • Startup credits and perks
  • Agent Skills
  • Publish a project

For enterprises

  • Start free company workspace
  • Submit a tool, product, or perk

Community

  • Community
  • Newsletter
  • Events
Xin

© 2026 tokensand, LLC. All rights reserved.

  • Terms
  • Privacy
  • Security
  • Data Processing
  • Status
  1. Hackathon
  2. Project gallery
  3. Beagle Brigade
Anonymous builderabout 2 hours agoJudging locked: Event build

Beagle Brigade

Scout sniffs every new npm and PyPI release for malware, in real time.

Review the project

Start with the source code, then open the demo or video if available.

View GitHub repository
Watch demo video
Demo video
Watch demo video
Project description
Beagle Brigade Scout sniffs every new npm and PyPI release for malware, in real time. Attackers have pushed malware into npm and PyPI thousands of times in the past year, and they did not break in: they published. A stolen maintainer token becomes a new version of a package you already depend on, and it executes on every laptop and CI runner that installs it, before anyone opens a file. Beagle Brigade watches both registries continuously, pulls each new release into a sandbox within seconds of publication, analyses it with Semgrep dataflow rules without ever executing it, scores it, and hands anything suspicious to an AI agent that returns a verdict an on-call engineer can act on in under a minute. Everything here is defensive. It watches public registries for malicious uploads, it is not pointed at anyone, and it never runs what it downloads.
Tools used
  • Guild.ai logoGuild.ai
  • ClickHouse logoClickHouse
  • PPi
  • SSemgrep
Project gallery
Project links
  • GitHub repository
  • Demo video
Tools used
  • Guild.ai logoGuild.ai
  • ClickHouse logoClickHouse
  • PPi
  • SSemgrep