I built a supply chain attack detector for npm and PyPI that scans packages before they reach your codebase

NPM install is stealing your passwords – I built a tool to catch it