logo

OSS Artifact Scanning at Scale Without Burning Your Token Budget

ID: 43014f6f-149c-5912-86a5-83d3d7e7c62f

STIX ID: report--43014f6f-149c-5912-86a5-83d3d7e7c62f

Feed Name: Nextron Systems

Threat Score
78/100

Date Published: 2026-06-19

Date Updated: 2026-06-20

Author: Marius Benthin

...
...

This report describes a production pipeline that indexes, scans, and triages artifacts from ten registries using deterministic THOR rules to prefilter findings and an LLM-based triage plus an on-demand agent (RuneAI) for deeper analysis; it presents a real detection where a malicious VS Code extension bundled Rust-built implants (Windows PE and macOS Mach-O) with GlassWorm overlap and notes the pipeline has reported more than 100 malicious packages across npm, VS Code/OpenVSX, and PyPI, explaining tradeoffs, costs, and limitations of rule-first design.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.