mlab-sh/postmortem
A static dependency scanner for Node.js, Python, and Rust projects. Resolves the lockfile graph, walks the vendored sources, and flags the patterns that typically show up in supply-chain compromises — install hooks, obfuscation, embedded IOCs (URLs, IPs, crypto wallets), and dangerous API surface.
GitHub repository with 5 stars and 0 forks.
Language: Rust
Topics: cli, mlab, open-source, scan