Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ore-mal-pkg-inspector — Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner | Kitploit
Tools/GitHubGitHub/rapticore/ore-mal-pkg-inspector
Static AnalysisVulnerability ScannersCode AnalysisInformation GatheringMalware AnalysisDevSecOpsThreat IntelligenceSupply Chain SecurityLearning & Education
GitHubrapticore/ore-mal-pkg-inspector

ore-mal-pkg-inspector

Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner

81174 months agoNot yet reviewed
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

OreWatch

Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner

Python Version License Status Ecosystems

A production-grade security tool for detecting malicious packages and supply chain threats across npm, PyPI, Maven, RubyGems, Go, and Cargo ecosystems. Leverages automated threat intelligence collection from trusted security sources to identify compromised dependencies in your projects.

OreWatch is the product and PyPI package name. The current source repository path still uses ore-mal-pkg-inspector.

Videos

Installation

https://github.com/rapticore/ore-mal-pkg-inspector/issues/2#issue-4215016110

OreWatch and Cursor

https://github.com/rapticore/ore-mal-pkg-inspector/issues/3#issue-4215017945

OreWatch and CodeX

https://github.com/rapticore/ore-mal-pkg-inspector/issues/4#issue-4215019385

OreWatch and Claude-Code

https://github.com/rapticore/ore-mal-pkg-inspector/issues/5#issue-4215021599


Table of Contents

  • The Problem
  • The Solution
  • Key Features
  • Why OreWatch?
  • Start Here
  • Quick Start
    • Prerequisites
    • Installation
    • First Scan
  • Usage
    • Basic Commands
    • Advanced Usage
    • Command-Line Reference
    • Background Monitoring
  • Adoption Guide
  • Distribution
    • Managed macOS Rollout
  • Logging & Debugging
  • Output & Reports
  • CI/CD Integration
  • Troubleshooting
  • FAQ
  • Contributing
  • Security Policy
  • Roadmap
  • License
  • Support
  • Acknowledgments

The Problem

Supply chain attacks are now the primary threat vector for software compromise. In 2024 alone, thousands of malicious packages were published to npm, PyPI, and other package registries, targeting developers with typosquatting, dependency confusion, and sophisticated malware campaigns like Shai-Hulud.

The challenge: Organizations and developers need to:

  • Scan dependencies across multiple programming ecosystems
  • Stay current with rapidly evolving threat intelligence from multiple sources
  • Detect not just known malicious packages but also indicators of compromise (IoCs)
  • Integrate security scanning into existing development workflows
  • Respond quickly to newly discovered threats

The gap: Existing solutions are often:

  • Limited to a single ecosystem (npm-only, PyPI-only, etc.)
  • Reliant on manual threat list maintenance
  • Lacking IoC detection capabilities
  • Difficult to integrate into automated pipelines
  • Proprietary black-box tools without transparency

The Solution

OreWatch addresses these challenges by providing:

Comprehensive Multi-Ecosystem Coverage: Single tool for npm, PyPI, Maven, RubyGems, Go, and Cargo packages

Automated Threat Intelligence: Dynamically collects and merges data from trusted security research sources

Active IoC Detection: Identifies Shai-Hulud attack patterns and other malicious code indicators beyond package name matching

CI/CD Ready: Designed for seamless integration into GitHub Actions, GitLab CI, Jenkins, and other automation platforms

Open Source and Transparent: Complete visibility into detection logic, data sources, and scanning methodology


Key Features

Multi-Ecosystem Support Scans npm, PyPI, Maven, RubyGems, Go, and Cargo packages with automatic ecosystem detection from project structure.

Unified Threat Intelligence Database Checks against dynamically collected malicious package databases from trusted security research sources.

Automatic Ecosystem Detection Intelligently identifies ecosystems from directory structure, file names, and can scan multiple ecosystems in a single run.

Indicators of Compromise (IoC) Detection Scans for Shai-Hulud attack patterns (original and 2.0 variants), malicious hooks, suspicious workflows, and known payload files.

Shai-Hulud Integration Cross-references npm packages against the comprehensive Shai-Hulud affected packages list from OreNPMGuard.

Structured JSON Reporting Generates machine-readable JSON reports with explicit threat-data metadata and SARIF-style file locations for findings.

Flexible Input Formats Supports standard dependency files (package.json, requirements.txt, etc.) and generic package lists (text, JSON, YAML).

Production-Ready Logging Configurable verbosity levels with --verbose and --debug flags for troubleshooting and audit trails.

Safe and Fast Read-only operations with no modifications to your code, optimized for scanning large codebases efficiently.


Why OreWatch?

vs. Single-Ecosystem Tools Most security scanners focus on one package manager. OreWatch provides unified protection across six major ecosystems, essential for modern polyglot development environments.

vs. Manual Threat Lists Static malicious package lists become outdated quickly. Our automated collectors fetch fresh threat intelligence daily from multiple authoritative sources.

vs. Package-Name-Only Detection Checking package names alone misses sophisticated attacks. IoC detection identifies malicious code patterns even in packages not yet on blocklists.

vs. Manual Security Audits Manual dependency reviews are time-consuming and error-prone. Automated scanning enables continuous security validation in every build.

vs. Commercial Black-Box Tools Proprietary tools lack transparency in detection logic. As an open-source project, every detection rule and data source is auditable.

Origin Story OreWatch was born from the development of OreNPMGuard, a specialized scanner for Shai-Hulud npm attacks. During that project, we recognized the need for broader multi-ecosystem coverage beyond npm. In December 2025, we extracted and enhanced the multi-ecosystem detection capabilities into this standalone tool, maintaining OreNPMGuard's focus on npm while enabling OreWatch to serve the wider developer community across all major package ecosystems.


Start Here

If you are adopting OreWatch for the first time, pick the smallest path that matches your workflow:

I want to...Use this pathStart with
scan one repo right nowCLI scanorewatch /path/to/project
protect local development in the backgroundsingleton monitororewatch monitor quickstart /path/to/project --client claude_code
use OreWatch from Cursor, Claude Code, or CodexMCP bridge`orewatch monitor quickstart /path/to/project --client <cursor
integrate with VS Code, PyCharm, or Xcodelocalhost APIorewatch monitor quickstart /path/to/project --client vscode
get visible macOS alerts and a native review surfacemenu bar apporewatch monitor menubar
validate builds in CIone-off CLI scanorewatch . --strict-data

Recommended first-run sequence for most developers:

Download Tool