Developer Builds AI Tool to Scan NPM and PyPI Daily for Malicious Packages
A developer has launched Authtics Advisories, an open-source system that uses Google's Gemini AI to automatically scan package registries for potentially malicious code. Each day, the tool selects 100 packages from both NPM and PyPI, runs them through an AI analysis pipeline, and generates a report submitted as a GitHub pull request for human review. The developer emphasized that AI findings are not treated as confirmed verdicts — a human reviewer retains final authority before any security advisory is issued. NPM and PyPI scans are staggered roughly two hours apart, with each full scan taking between 30 minutes and an hour to complete. The developer plans to expand coverage to additional registries and is also working on a companion tool called Authtics NPM, which would warn users of potential risks at the point of package installation.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in