PulseGateIndexCategoriesUpdatesLive intelligence on AI-era software— indexed in the last hour
Coverage—projects tracked
Freshness—newest entry
Cadence—last week average · — today
Index9 markets86 categories
PulseGate

Live intelligence on the AI-era software market — apps, models, agents and infrastructure.

Most of it never reaches an official store. PulseGate maps the whole market — every category, worldwide — and measures how it moves: what’s launching, what’s gaining, what’s going quiet.

FollowGitHubX (Twitter)LinkedIn
Platform
All AppsFull IndexCategoriesIndustry UpdatesData SourcesCoverage RulesGlossaryEmbed Widget
Support
Help CenterSubmit your projectReport an Issue
Company
AboutDimaxiaPress & DataContactPlatform Status
Legal
PrivacyTermsDisclaimer
Dimaxia · Dymaxio s.r.o. · Prague, Czechia · © 2026WatchlistSitemapSystem status
PulseGateHEhemlock-scan
Visit↗
Skip to content
  1. Index›
  2. Other dev tools›
  3. hemlock-scan
← Back to the index
HE

hemlock-scan

PyPI·Infrastructure

hemlock-scan is an open-source supply-chain scanner for npm and PyPI packages. It analyzes package behavior to identify potential attacks such as typosquatting and other malicious patterns, going beyond traditional CVE-based vulnerability scanning. It is designed for developers and security teams integrating it into their CI/CD pipelines or local workflows.

Open SourceMITCLI
Visit PyPI↗
1star
5features
2026since

Overview

5 features

hemlock-scan is an Other dev tools project. It focuses on detecting malicious or typo-squatted packages in npm and PyPI supply chains that exhibit attack-like behavior but lack a published CVE. hemlock-scan is an open-source project aimed at developers. hemlock-scan is open source under the MIT license. hemlock-scan is available on the command line.

xzycd builds and maintains hemlock-scan, and it first shipped in 2026. Development happens publicly on GitHub with 20 commits in the last 90 days. Among its 5 catalogued features are Supply Chain Scanning, Malicious Behavior Detection, and Typosquatting Detection.

Summary written by a language model from the project’s public pages.

  • ✓Supply Chain Scanning
  • ✓Malicious Behavior Detection
  • ✓Typosquatting Detection
  • ✓npm Support
  • ✓PyPI Support
Tags
supply-chain-securitydependency-scanningtyposquatting-detectionsastsbom

Built with & integrations

Runs on
CLI

Trust & compliance

License
MIT
Verified signals
✓HTTPS✓Open Source✓GitHub · ★ 1✓Active maintenance

Indexing history

1

What PulseGate has recorded for this listing

  1. Indexed31 Jul · 23:29 UTC
    hemlock-scan verified against its public source
    Source: PulseGate · Open ↗

Frequently asked questions about hemlock-scan

What is hemlock-scan?
Hemlock-scan focuses on detecting malicious or typo-squatted packages in npm and PyPI supply chains that exhibit attack-like behavior but lack a published CVE. It is catalogued under Other dev tools on PulseGate.
Who is hemlock-scan for?
hemlock-scan is an open-source project built for developers.
Is hemlock-scan free?
Yes — hemlock-scan is open source under the MIT license and free to use.
What platforms does hemlock-scan run on?
hemlock-scan runs on the command line.
Is hemlock-scan still active?
The GitHub repository shows 20 commits in the last 90 days.
What are alternatives to hemlock-scan?
Similar projects tracked by PulseGate include git-build-commit, funkuino, and click-docs.git-build-commitfunkuinoclick-docs
Who develops hemlock-scan?
hemlock-scan is developed by xzycd.
How long has hemlock-scan been around?
hemlock-scan first shipped in 2026.

At a glance

Platforms
Cli
Languages
English
Open source
Yes · ★ 1
License
MIT
First seen
31 Jul 2026
Built for
developers
Model
Open source
Solves
Detecting malicious or typo-squatted packages in npm and PyPI supply chains that exhibit attack-like behavior but lack a published CVE.

Registered as

GitHub
xzycd/hemlock
PyPI
hemlock-scan

Developer

xzycd
Small team
↗ GitHub

Open source

View on GitHub →
Stars
1
Forks
0
Open issues
0
Last commit
31 Jul 2026
Commits 90d
20
Contributors
2
Authorship
Small team
Default branch
master
Latest release
v0.5.0 · 31 Jul 2026

Live coverage

Identity confidence
Low · 64
Indexed
31 Jul 2026
Lifecycle
Alive
First seen
Jul 2026
Last seen
31 Jul 2026
Identity audit (13)
Slug
hemlock-scan-pypi-org
Lifecycle state recorded
31 Jul 2026
Verification state
Indexed for public listing
Listing state
Listed: yes
Index status
Included in index
Latest evidence snapshot
31 Jul 2026
Timeline basis
Indexed-at chronology (no inferred launch/funding milestones).
Name from
Written by a language model from the project's public pages.
Category from
Assigned by a language model.
Summary from
Written by a language model from public pages.
Languages from
Detected by a language model from page content.
Last updated
4 Aug 2026
Canonical URL
https://pypi.org/project/hemlock-scan

Ship this? Send a correction — no account, and you get a link to follow it.

Also in Other dev tools

Same category — not a similarity match

  • GIgit-build-commitpypi.org
  • FUfunkuinopypi.org
  • CLclick-docsgithub.com
  • CNcnpj-valpypi.org
  • CNcnpj-genpypi.org
  • PRpre-commit-vauxoopypi.org