hemlock-scan is an open-source supply-chain scanner for npm and PyPI packages. It analyzes package behavior to identify potential attacks such as typosquatting and other malicious patterns, going beyond traditional CVE-based vulnerability scanning. It is designed for developers and security teams integrating it into their CI/CD pipelines or local workflows.
hemlock-scan is an Other dev tools project. It focuses on detecting malicious or typo-squatted packages in npm and PyPI supply chains that exhibit attack-like behavior but lack a published CVE. hemlock-scan is an open-source project aimed at developers. hemlock-scan is open source under the MIT license. hemlock-scan is available on the command line.
xzycd builds and maintains hemlock-scan, and it first shipped in 2026. Development happens publicly on GitHub with 20 commits in the last 90 days. Among its 5 catalogued features are Supply Chain Scanning, Malicious Behavior Detection, and Typosquatting Detection.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Same category — not a similarity match