v0.1.0-betaWindowsFREE

Transform Your
Supply Chain
Security.

A blazingly fast, locally-executing desktop agent that scans your machine for malicious packages and zero-day vulnerabilities in milliseconds.

Zero cloud data leakage
100% local execution
Open-source core
bash - pkgwatch
~/projectpkgwatch scan --profile baseline
Loading OSV threat feed... [DONE]
Scanning 2,986 local packages...
[!]CRITICAL THREAT DETECTED
Package: STMicroelectronics.stm32
Confidence: HIGH (OSV Match)
✓ Scan completed in 0.1s
pkgwatch
PackagesVulnerabilitiesHistorySettings
✓ completed in 19.8s
Run Scan
ACTIVE THREATS
0
from threat feed
PACKAGES
2,986
discovered
ECOSYSTEMS
5
registries
SUSPICIOUS HIGH
2,230
SUSPICIOUS MED
756
FILTER
browser-extension50
editor-extension38
go204
npm2552
pypi162
ECOSYSTEM ↑PACKAGE NAMEVERSIONCONFIDENCE
editor-extension
STMicroelectronics.stm32-vscode-extensionv3.9.0
HIGH
editor-extension
ms-vscode.cpp-devtoolsv0.5.13
HIGH
editor-extension
ms-vscode.remote-explorerv0.5.0
HIGH
editor-extension
STMicroelectronics.stm32cube-ide-corev1.3.0
HIGH
49–60 of 2,986
1
4
5
6
249
page 5 of 249
THE PROBLEM

Enterprise tools are
breaking your flow.

Modern supply chain attacks are fundamentally different. Your tools need to be too.

Current Reality
Supply chain attacks (typosquatting, compromised releases) bypass standard AV entirely
Enterprise scanners upload your codebase to remote servers—leaking sensitive IP
Cloud-based tools take minutes per scan, breaking developer flow and CI pipelines
Zero-day packages slip through while CVE databases update with a 24–72 hour lag
No heuristic risk scoring—only known-bad signatures with no behavioral context
pkgwatch
Detects typosquatting and novel zero-day packages heuristically before they ever run
Runs entirely on your local filesystem—your code never leaves your machine
Sub-second scans run silently in background; zero interruption to developer workflow
Daily-updated OSV catalog ensures guaranteed CVE and known-malware coverage
Confidence scoring: High / Medium / Low risk for every flagged package
HOW IT WORKS

Four layers of
defense.

Built on open standards. Executed locally. Zero compromise.

RUST + GO

Dual-Engine Architecture

Powered by the open-source Bumblebee Go binary wrapped in a hyper-optimized Rust/Tauri desktop shell. Native performance, sub-500ms cold starts, zero overhead.

AI HEURISTICS

Heuristic Zero-Day Analysis

Analyzes package metadata, publication age, maintainer history, and behavioral signals. Assigns High/Medium/Low confidence scores so you know which suspicious packages to act on first.

OSV + CVE

Deterministic Threat Intel

Fetches a daily-updated catalog.json compiled from Google OSV. Every known CVE and malware signature matched locally—guaranteed coverage with no latency from cloud round-trips.

100% LOCAL

Privacy-First by Design

Scans run entirely on your filesystem. No code, no dependency manifests, no telemetry ever leaves your machine. Your IP, your supply chain data, stays yours.

SUPPORTED ECOSYSTEMS

Covers the ecosystems
that matter.

8+ package managers. One agent. Fully offline.

NPM
PyPI
Cargo
Go Modules
Maven
RubyGems
Homebrew
APT
NPM
PyPI
Cargo
Go Modules
Maven
RubyGems
Homebrew
APT
NPM
PyPI
Cargo
Go Modules
Maven
RubyGems
Homebrew
APT
PRICING

Start for free.
Scale with your team.

No credit card. No account. Just download and scan.

Developer Edition
$0/ forever

Full-featured local desktop agent. No cloud, no account, no catches.

Local desktop app (Windows)
Heuristic scanning engine
Daily OSV threat feed (automatic)
8+ supported ecosystems
Confidence scoring: High/Med/Low
Open-source core (Bumblebee)
COMING SOON
Enterprise Teams
Custom

For engineering orgs requiring fleet visibility, CI/CD pipeline enforcement, and compliance reporting.

Everything in Free, plus:
Centralized CISO Fleet Dashboard
CI/CD PR blocking (GitHub/GitLab)
Automated remediation auto-PRs
Private registry scanning (Artifactory)
SOC2 & ISO27001 compliance exports
SSO & SAML access control
DEVELOPER ROADMAP

Currently In Development

We are actively expanding core platform support. These features will be available in the free Developer Edition very soon.

macOS Native

Full support for Intel and Apple Silicon (M1/M2/M3) chips. Packaged as a signed, native .dmg application.

Linux Desktop

Support for major distributions including Ubuntu, Debian, and Fedora. Distributed via .deb and .AppImage.

System Tray Daemon

Run pkgwatch silently in the background. It will actively monitor your node_modules and site-packages and alert you if a malicious dependency is pulled down.