Skip to main content
Back to all repositories

Supply-chain malware scanner for Git repos. Finds droppers committed into the repo itself — the kind npm audit can't see because there's no malicious dependency. Runs on git clone or when VS Code opens the folder. Kills the loader, scans every repo you can reach, purges it from history.

5stars2forks1watchers/subscribers1issues
clipboard-stealerdevsecopsetherhidinggithub-securityincident-responseinfoseclinuxmacosmalwaremalware-detectionmalware-scannernodejsnpmnpm-securitysecurityshai-huludsupply-chain-attacksupply-chain-securitythreat-detectionvscode
Language
Shell
License
MIT License
Size
283 KB
Created
Aug 24, 2026
Last Updated
Sep 10, 2026
Last Pushed
Sep 10, 2026

Available Plugins

Loading plugins...

Evaluate before installing

  1. Review the source repository, recent maintenance, and license on GitHub.
  2. Read the marketplace manifest and plugin source files before running commands.
  3. Start with the smallest required permission set and validate behavior in a safe environment.