CLU

2 minutes read

Overview

CLU is a Malicious PyPI and npm package hunter that I decided to build after a recovering from new years eve celebrations in 2026.

CLU monitors every update in the PyPI and npm feeds for new packages, runs heuristic analysis, yara patterns and also conducts an LLM-based code review. When it finds something it will alert your team via discord integration.

⚠️ SECURITY NOTE: This tool analyzes potentially malicious code. Always run inside a container as a non-root user.

Other Features

Four-Stage Analysis Pipeline:

Real-Time Data Pipeline:

Deployment & Usability:

Findings Management:

Where to find CLU

https://github.com/trapdoorsec/clu