Where Chainsaw fits
Pinning, cooldowns, blocklists, SCA. Chainsaw sits behind them.
They solve different parts of the problem, and most of them stack.
| Approach | When it acts | What it's good at | Where it stops |
|---|---|---|---|
| Lockfile pinning | At resolve | Reproducible builds, no surprise upgrades. | A later compromised version still gets pulled once you bump it. Doesn't judge intent. |
| Dependency cooldown pnpm minimumReleaseAge | At resolve | Cheap, free, catches fast-reverted compromises. | Probabilistic: relies on someone else getting burned first. No org-wide enforcement. A Shai-Hulud-style worm spreads through trusted maintainers and packages that already passed the window. |
| Malicious-package blocklist Safe Chain, etc. | At install | Blocks known-bad against a feed, free. | Only as good as the feed's coverage. A blocklist isn't a policy you can shape per team. |
| SCA scanner Snyk · Sonatype · Mend | After install | Inventory, CVE matching, license checks. | Reports after the install script already ran. CVE-centric. |
| Chainsaw — free CLI | At install, offline | Blocks known-malicious + typosquats for npm/PyPI/Go/Rust/Ruby, same engine each. No account. | No deep install-script behavioral analysis on the laptop — that's the proxy. |
| Chainsaw — proxy | At install, on the path | 25 signals beyond CVE. Monitor mode. Enforcement across CI, endpoint, network. | npm and PyPI have full behavioral parity. Some signals thin or absent on registries without per-version publisher metadata. |
Measured, one run
Numbers we can reproduce
An earlier 0.00% didn't reproduce, so it was re-measured. The verdict that refuses an install, one run:
| Real malware hard-blocked | Top packages false-blocked |
|---|---|
| 43.7% · 104 of 238 | 0.47% · 4 of 860 |
One 1,098-package corpus, own-bytes only, before the 231k-entry known-malicious feed floor. The corpus builder and harness are in the repo.
The four false blocks
Each is an indicator in genuine shipping code: tqdm's Telegram progress-bar
backend, ipython's %dpaste magic, huggingface-hub's
documented webhook endpoint, and browser-use, which reads browser
credential-store paths as its entire purpose.
The looser "a signal fired" measure (dated)
It surfaces, it doesn't block: 69% of real malware at a 5% signal rate on benign packages. Measured on a superseded 597-sample corpus and not re-run, so it is never quoted beside 0.47%. Both cells of one row, never one cell from each.
No product pitch — just the teardowns
A teardown of each notable package attack
What happened, what stopped it, and where Chainsaw would and wouldn't have caught it.