Supply Chain Monitor: Automated Detection of Package Compromises
This repository profile is provided by osrepos.com, an open source repository discovery platform.

Summary
Supply Chain Monitor is a powerful tool by Elastic designed to automatically detect supply chain compromises in popular PyPI and npm packages. It polls registries for new releases, diffs them against predecessors, and uses an LLM via Cursor Agent CLI to classify changes as benign or malicious. Malicious findings trigger immediate Slack alerts, enhancing security for your software dependencies.
Repository Information
Topics
Click on any tag to explore related repositories
Use at your own risk
OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of code from these repositories is the user's own responsibility. Always review the repository, source code, dependencies, licenses, and security implications before running or installing anything. OSRepos is not responsible for issues, damages, or losses resulting from third-party repositories.
Introduction
The Supply Chain Monitor by Elastic offers an automated solution for safeguarding your software dependencies against supply chain attacks. This Python-based tool continuously monitors the top PyPI and npm packages for new releases. When a new version is detected, it performs a detailed diff against the previous release and leverages an LLM (via Cursor Agent CLI) to analyze the changes. The LLM is specifically prompted to identify suspicious patterns, classifying diffs as either benign or malicious. If a malicious change is identified, the system automatically triggers a Slack alert, providing early warning of potential compromises.
The monitor is designed to look for various indicators of compromise, including obfuscated code, unexpected network calls, file system writes to sensitive locations, process spawning, credential exfiltration, and typosquatting.
Installation
To get started with Supply Chain Monitor, you'll need Python 3.9+ and the Cursor Agent CLI.
Prerequisites
- Python 3.9+: Install runtime dependencies using
pip install -r requirements.txt. Therequirements.txtfile is located in the repository. - Cursor Agent CLI: This is the standalone
agentbinary, not the IDE.
Installing Cursor Agent CLI
Windows (PowerShell):
irm 'https://cursor.com/install?win32=true' | iex
macOS / Linux:
curl https://cursor.com/install -fsS | bash
Verify your installation with:
agent --version
You must also authenticate with Cursor using agent login or by setting the CURSOR_API_KEY environment variable.
Slack Configuration
For receiving alerts, configure Slack by placing your bot token in etc/slack.json:
{
"url": "https://hooks.slack.com/services/...",
"bot_token": "xoxb-...",
"channel": "C01XXXXXXXX"
}
Ensure your bot has chat:write scope on the target channel, and channel is set to the Slack channel ID where alerts should be posted.
Examples
The monitor.py script is the main orchestrator. Here are some quick start commands:
- One-shot analysis: Analyze releases from the last approximately 10 minutes, then exit.
python monitor.py --once - Continuous monitoring: Monitor the top 1000 packages from both ecosystems, polling every 5 minutes.
python monitor.py --top 1000 --interval 300 - Production setup: Monitor the top 15000 packages, polling every 5 minutes, with Slack alerts enabled.
python monitor.py --top 15000 --interval 300 --slack - npm only: Monitor the top 5000 npm packages.
python monitor.py --no-pypi --npm-top 5000 - PyPI only: Monitor PyPI packages exclusively.
python monitor.py --no-npm
Why Use It
Supply Chain Monitor provides crucial benefits for maintaining the security of your software projects:
- Proactive Threat Detection: It continuously monitors popular package registries, identifying potential compromises before they can impact your systems.
- LLM-Powered Analysis: By leveraging an LLM, the tool can intelligently analyze code differences, detecting sophisticated obfuscation, malicious network calls, and other advanced attack techniques that might evade traditional static analysis.
- Real-time Alerts: Immediate Slack notifications for malicious findings enable rapid response to security incidents.
- Broad Coverage: Monitors both PyPI and npm, covering a vast array of open-source dependencies.
- Lightweight Operation: Designed to be efficient, making only a few API calls per poll interval and per new release, minimizing overhead.
Links
- GitHub Repository: https://github.com/elastic/supply-chain-monitor
Related repositories
Similar repositories that may be relevant next.

oh-my-hermes: Enhance Hermes Agent with Advanced AI Workflow and Memory
September 17, 2026
oh-my-hermes is an all-in-one plugin designed to significantly enhance the Hermes Agent. It provides advanced coding intelligence, a robust long-term memory system, and optimized workflow packages, transforming standard Hermes requests into structured, actionable tasks with clear operational layers.
ASC: A Super Fast Android Decompiler for Mobile Reverse Engineering
September 17, 2026
ASC is an innovative and exceptionally fast Android decompiler front-end, specifically designed for mobile researchers and agents. It redefines traditional decompilation by directly querying compiled artifacts, offering on-demand code extraction and analysis without heavy preprocessing. This approach results in significantly reduced memory usage and lightning-fast performance, even on large APKs.

Open Index: A Deterministic Memory Layer for Your AI Agents
September 16, 2026
Open Index is a powerful tool for building domain-specific, accurate, and structured data that AI agents can effectively operate on. It enables the creation of a "brain," a searchable and continuously improving context graph tailored to any domain. This system ensures agents have access to reliable, up-to-date information, enhancing their capabilities and decision-making processes.
tooltrim: Drastically Reduce LLM Agent Tool Output Tokens, Improve Accuracy
September 16, 2026
tooltrim provides drop-in compression for LLM agent tool outputs, drastically cutting tokens while often improving answer accuracy. This provider-agnostic solution offers content-aware compression, faithfulness benchmarks, and seamless integration with popular frameworks or as an OpenAI-compatible proxy.
Source repository
Open the original repository on GitHub.
13 counted GitHub visits