Pqurp – Quarantine Window for Packages to Prevent Supply Chain Attacks
Speculative protocol for package quarantine without a reference implementation or registry buy-in.
Detect supply chain attacks in Python dependencies. Catches .pth injection, encoding obfuscation, typosquatting, and compromised packages. Zero dependencies, runs in 2 seconds.
Catches .pth injection vectors from the litellm attack when Snyk and Dependabot miss them.
Python developers and security engineers
Snyk · Dependabot · Safety
Speculative protocol for package quarantine without a reference implementation or registry buy-in.
Behavioral malware scanning before install, unlike pip-audit.
Reimplements dependency functions locally with test verification, challenging the "dependencies are good" mantra.
Forensic triage CLI with verdict system for axios IOC detection.
Finally, pytest for AI tool calls when evals only test intelligence.
Dependabot already does this without the AI agent overhead.