3 ms·
I've been building an OSS tool to detect software supply-chain attacks: https://github.com/ossillate-inc/packj https://github.com/ossillate-inc/packj Packj use
by ashishbijlani 2mo ago
I've been building an OSS tool to detect software supply-chain attacks: https://github.com/ossillate-inc/packj https://github.com/ossillate-inc/packj
Packj uses static+dynamic code/behavioral analysis to scan for indicators of compromise (e.g., spawning of shell, use of SSH keys, network communication, use of decode+eval, etc). It also checks for several metadata attributes to detect impersonating packages (typo squatting).
- koalak 2mo ago[dead]