nowfound

Alternatives

Products that do what Vet now supports detecting malicious packages does

If you are worried about the recent Lazarus group software supply chain attack, you should consider having guard rails that is more than conventional SCA. `vet` detects the package (version) published in the report as malware. Try out vet, its free and open source: https://github.com/safedep/vet More details on the attack: https://www.nodejs-security.com/blog/north-korea-malware-on-...

  1. 1
    Arnica97

    Behavior based software supply chain security

    2022

  2. 2IB

    Linux Foundation survey says 70-90% of modern software constitute OSS code. Yet we are stuck with tools that scan only for vulnerabilities in 3rd party libraries and that too with high degree of false positives. I built `vet` for policy and data driven analysis of 3rd party packages that goes beyond only vulnerability and allows codifying organisational policies related to OSS consumption. https://github.com/safedep/vet Looking forward to feedback and suggestions from HN :)

    2023 · github.com

  3. 3
    NFT Guard236

    Protect yourself from fake NFTs and crypto scams

    2022

  4. 4

    Secure your JavaScript supply chain – block malware packages

    2022

  5. 5

    Protect yourself from crypto scams and frauds

    2018

  6. 6

    Identify persistently installed malware

    2017

  7. 7
    Refuse84

    Block vulnerable package installs for you and your AI

    Jun 2026 · refuse.dev

  8. 8PA
  9. 9AM
  10. 10PQ
  11. 11IB

    Hello HN, around October last year, I started to work on campaignkit.cc as a side project. It is a service to detect invalid and malicious email addresses. You can upload text files, and use the REST API or direct integration to retrieve a detailed report for each email address. End of March I added Stripe Payments and got my first paying customers via SEM. A coworker suggested starting a Show HN thread, so here we are :) I used golang for the backend since I wanted something lightweight with fast compilation times (coming from scala). For the frontend, I'm using Next.js and TailwindUI. On…

    2022 · campaignkit.cc

  12. 12DI

    I built an open-source malware detection daemon that monitors all running processes in real-time using ML + heuristics. No kernel modules or eBPF required. Key points: - Polls &#x2F;proc for new processes (works on any Linux kernel 2.6+) - Random Forest model trained on EMBER 2018 dataset (2.3M samples) - Heuristic rules for crypto miners, ransomware, rootkits - ~20MB RAM, <1% CPU, sub-millisecond scan latency - Pure C, zero runtime dependencies - Model embedded directly in binary (50KB) Why I built this: Existing solutions either require modern kernels (eBPF) or are heavy&#x2F;proprietary.…

    Nov 2025 · github.com

  13. 13AD

    I use no-defender, but noticed it got sent down the memory hole. Here's an updated version that doesn't ship any 3rd party binaries.

    2025 · github.com

  14. 14LF

    Hi HN, I just wanted to share what I have been working on for the past few months: A firmware analyzer for embedded Linux systems that helps uncovering security issues running entirely in the browser. This is a very early Alpha. It is going to be rough around the edges. But I think it provides quite a lot of value already. So please go ahead and drop a firmware (only .tar rootfs archives for now) and try to break it :)

    Mar 2026 · xray.boldwark.com

  15. 15

    Safeguard & Self-Heal your Software Supply Chain (Zero Days)

    27d ago · safeguard.sh

  16. 16VA
  17. 17

    Hand it a ticket. Come back to a green PR. Free and local.

    4d ago · klaussy.com

  18. 18BT
  19. 19MA
  20. 20TM

    Figured I'd track the popular coding agents to see merge and approval rates. At first I was tracking Opened vs. Approved, but realized most people aren't approving; they just merge. I haven't found a way to reliably track the other agents (Jules, Devin, etc), since they don't have a standardized branch naming convention. Interesting to watch this over time. Open to ideas.

    2025 · github.com

  21. 21AC

    Let me start by saying thank you for taking the time to review it. I hope it is useful to someone. It can be downloaded and reviewed at no cost with the following offer code: hackernews, to be entered during the purchasing process. Reviews on the software itself, and marketing advice on how to grow sales is appreciated. Site: http:&#x2F;&#x2F;baileyssoftware.com&#x2F; Notes: - I am aware of the @gmail address used, but I don't want to pay for a service (e.g. https:&#x2F;&#x2F;gsuite.google.com&#x2F;) until I have the monthly income to support it. - If there is enough interest I plan to add…

    2017

  22. 22

    Catch Malicious npm and PyPI Packages by Their Behavior

    25d ago · tazarsec.dev

  23. 23

    Fast environment scan for hidden issues before you ship

    15d ago · github.com

Ranked by how close each launch is in meaning, then by votes. Refine with a description →