I built Computer Police for our team to never be in this situation again.
It's designed to block that earlier. It runs a local registry proxy between your package manager and npm/PyPI, and stops confirmed-malicious packages before they touch disk.
It's deliberately narrow: malware only, no CVE scanning, no heuristics, no telemetry, no root, and removable with one command. Works locally, in CI, and in agent sandboxes.
hootz•35m ago
kannthu•22m ago
+ To be clear, this tool does not solve the problem if you are one of the first people to get infected; it minimizes your chance if you are the N-th person