Where Chainsaw fits

Pinning, cooldowns, blocklists, SCA. Chainsaw sits behind them.

They solve different parts of the problem, and most of them stack.

Approach When it acts What it's good at Where it stops
Lockfile pinning At resolve Reproducible builds, no surprise upgrades. A later compromised version still gets pulled once you bump it. Doesn't judge intent.
Dependency cooldown pnpm minimumReleaseAge At resolve Cheap, free, catches fast-reverted compromises. Probabilistic: relies on someone else getting burned first. No org-wide enforcement. A Shai-Hulud-style worm spreads through trusted maintainers and packages that already passed the window.
Malicious-package blocklist Safe Chain, etc. At install Blocks known-bad against a feed, free. Only as good as the feed's coverage. A blocklist isn't a policy you can shape per team.
SCA scanner Snyk · Sonatype · Mend After install Inventory, CVE matching, license checks. Reports after the install script already ran. CVE-centric.
Chainsaw — free CLI At install, offline Blocks known-malicious + typosquats for npm/PyPI/Go/Rust/Ruby, same engine each. No account. No deep install-script behavioral analysis on the laptop — that's the proxy.
Chainsaw — proxy At install, on the path 25 signals beyond CVE. Monitor mode. Enforcement across CI, endpoint, network. npm and PyPI have full behavioral parity. Some signals thin or absent on registries without per-version publisher metadata.

Measured, one run

Numbers we can reproduce

An earlier 0.00% didn't reproduce, so it was re-measured. The verdict that refuses an install, one run:

Real malware hard-blocked Top packages false-blocked
43.7% · 104 of 238 0.47% · 4 of 860

One 1,098-package corpus, own-bytes only, before the 231k-entry known-malicious feed floor. The corpus builder and harness are in the repo.

The four false blocks

Each is an indicator in genuine shipping code: tqdm's Telegram progress-bar backend, ipython's %dpaste magic, huggingface-hub's documented webhook endpoint, and browser-use, which reads browser credential-store paths as its entire purpose.

The looser "a signal fired" measure (dated)

It surfaces, it doesn't block: 69% of real malware at a 5% signal rate on benign packages. Measured on a superseded 597-sample corpus and not re-run, so it is never quoted beside 0.47%. Both cells of one row, never one cell from each.

No product pitch — just the teardowns

A teardown of each notable package attack

What happened, what stopped it, and where Chainsaw would and wouldn't have caught it.