Beagle Brigade
Scout sniffs every new npm and PyPI release for malware, in real time.
Attackers have pushed malware into npm and PyPI thousands of times in the past year, and they did not break in: they published. A stolen maintainer token becomes a new version of a package you already depend on, and it executes on every laptop and CI runner that installs it, before anyone opens a file. Beagle Brigade watches both registries continuously, pulls each new release into a sandbox within seconds of publication, analyses it with Semgrep dataflow rules without ever executing it, scores it, and hands anything suspicious to an AI agent that returns a verdict an on-call engineer can act on in under a minute.
Everything here is defensive. It watches public registries for malicious uploads, it is not pointed at anyone, and it never runs what it downloads.