
Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner
Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner
A production-grade security tool for detecting malicious packages and supply chain threats across npm, PyPI, Maven, RubyGems, Go, and Cargo ecosystems. Leverages automated threat intelligence collection from trusted security sources to identify compromised dependencies in your projects.
OreWatch is the product and PyPI package name. The current source repository path still uses ore-mal-pkg-inspector.
https://github.com/rapticore/ore-mal-pkg-inspector/issues/2#issue-4215016110
https://github.com/rapticore/ore-mal-pkg-inspector/issues/3#issue-4215017945
https://github.com/rapticore/ore-mal-pkg-inspector/issues/4#issue-4215019385
https://github.com/rapticore/ore-mal-pkg-inspector/issues/5#issue-4215021599
Supply chain attacks are now the primary threat vector for software compromise. In 2024 alone, thousands of malicious packages were published to npm, PyPI, and other package registries, targeting developers with typosquatting, dependency confusion, and sophisticated malware campaigns like Shai-Hulud.
The challenge: Organizations and developers need to:
The gap: Existing solutions are often:
OreWatch addresses these challenges by providing:
Comprehensive Multi-Ecosystem Coverage: Single tool for npm, PyPI, Maven, RubyGems, Go, and Cargo packages
Automated Threat Intelligence: Dynamically collects and merges data from trusted security research sources
Active IoC Detection: Identifies Shai-Hulud attack patterns and other malicious code indicators beyond package name matching
CI/CD Ready: Designed for seamless integration into GitHub Actions, GitLab CI, Jenkins, and other automation platforms
Open Source and Transparent: Complete visibility into detection logic, data sources, and scanning methodology
Multi-Ecosystem Support Scans npm, PyPI, Maven, RubyGems, Go, and Cargo packages with automatic ecosystem detection from project structure.
Unified Threat Intelligence Database Checks against dynamically collected malicious package databases from trusted security research sources.
Automatic Ecosystem Detection Intelligently identifies ecosystems from directory structure, file names, and can scan multiple ecosystems in a single run.
Indicators of Compromise (IoC) Detection Scans for Shai-Hulud attack patterns (original and 2.0 variants), malicious hooks, suspicious workflows, and known payload files.
Shai-Hulud Integration Cross-references npm packages against the comprehensive Shai-Hulud affected packages list from OreNPMGuard.
Structured JSON Reporting Generates machine-readable JSON reports with explicit threat-data metadata and SARIF-style file locations for findings.
Flexible Input Formats Supports standard dependency files (package.json, requirements.txt, etc.) and generic package lists (text, JSON, YAML).
Production-Ready Logging
Configurable verbosity levels with --verbose and --debug flags for troubleshooting and audit trails.
Safe and Fast Read-only operations with no modifications to your code, optimized for scanning large codebases efficiently.
vs. Single-Ecosystem Tools Most security scanners focus on one package manager. OreWatch provides unified protection across six major ecosystems, essential for modern polyglot development environments.
vs. Manual Threat Lists Static malicious package lists become outdated quickly. Our automated collectors fetch fresh threat intelligence daily from multiple authoritative sources.
vs. Package-Name-Only Detection Checking package names alone misses sophisticated attacks. IoC detection identifies malicious code patterns even in packages not yet on blocklists.
vs. Manual Security Audits Manual dependency reviews are time-consuming and error-prone. Automated scanning enables continuous security validation in every build.
vs. Commercial Black-Box Tools Proprietary tools lack transparency in detection logic. As an open-source project, every detection rule and data source is auditable.
Origin Story OreWatch was born from the development of OreNPMGuard, a specialized scanner for Shai-Hulud npm attacks. During that project, we recognized the need for broader multi-ecosystem coverage beyond npm. In December 2025, we extracted and enhanced the multi-ecosystem detection capabilities into this standalone tool, maintaining OreNPMGuard's focus on npm while enabling OreWatch to serve the wider developer community across all major package ecosystems.
If you are adopting OreWatch for the first time, pick the smallest path that matches your workflow:
| I want to... | Use this path | Start with |
|---|---|---|
| scan one repo right now | CLI scan | orewatch /path/to/project |
| protect local development in the background | singleton monitor | orewatch monitor quickstart /path/to/project --client claude_code |
| use OreWatch from Cursor, Claude Code, or Codex | MCP bridge | `orewatch monitor quickstart /path/to/project --client <cursor |
| integrate with VS Code, PyCharm, or Xcode | localhost API | orewatch monitor quickstart /path/to/project --client vscode |
| get visible macOS alerts and a native review surface | menu bar app | orewatch monitor menubar |
| validate builds in CI | one-off CLI scan | orewatch . --strict-data |
Recommended first-run sequence for most developers: