Published September 10, 2026 | Version v0.2.0

chainwatch

Authors/Creators

Description

LLM-assisted supply chain diff analyzer for detecting malicious npm/PyPI package updates. Combines semantic diff analysis (Claude) with threat intelligence feeds (OSV, Rekor/Sigstore, OpenSSF Scorecard, and a new-dependency provenance heuristic) and a ground-truth corpus of real, independently-sourced-and-verified malicious package incidents. Reports record per-stage timings and explicit caveats about evidence the LLM did not see; a --strip-comments control isolates how much of a score comes from prose rather than code.

Notes

If you use this software or its accompanying ground-truth corpus, please cite it as below.

Files

erxxc/chainwatch-v0.2.0.zip

Files (841.7 kB)

Name Size Download all
md5:5c2643b6061059d0d84acff9b92ab354
841.7 kB Preview Download

Additional details

Related works

Is supplement to
Software: https://github.com/erxxc/chainwatch/tree/v0.2.0 (URL)

Software