Detection
6 tutorials in this category.
01
How to Detect Known Malware in Your Supply Chain
Understand Chainsaw's malware index powered by OpenSSF data, review malware detections, and configure automatic blocking of malicious packages.
02
How to Detect and Prevent Typosquatting Attacks
Understand Chainsaw's BK-tree typosquat detection, review flagged packages, and create policies that block suspected typosquats.
05
How to Detect Install-Script Exfiltration
Block PhantomRaven-style dynamic install dependencies and obfuscated eval(atob(...)) payloads with the hasInstallScript and installScriptFetchesRemote conditions.
06
How to Detect Compromised Packages with publisherChanged and versionAnomaly
Catch Axios-style maintainer-takeover drops, semver regressions, multi-major skips, and backdated publishes before they reach your builds.
07
How to Detect Hidden Unicode Payloads (GlassWorm / Trojan Source)
Block packages carrying zero-width, bidi-override, or Unicode-tag payloads with the hasHiddenUnicode condition.
08
How to Detect Shai-Hulud-Style Worm Bursts
Catch attackers auto-publishing hundreds of packages from a compromised token with the publishVelocityAnomaly condition.