datadog-security-labs · Crawled Jul 18, 2026

Introducing GuardDog 3.0: A new rules engine, transparent sandboxing, and more

2 IoCs
Read original article ↗

AI Summary

GuardDog 3.0 is an open-source security tool designed to detect malicious PyPI and npm packages by analyzing source code for suspicious behaviors. It introduces a new risk scoring engine that evaluates the likelihood of a package being malicious based on attack chain completeness, capability detection, and code sophistication. The tool now uses YARA for more efficient and scalable scanning, replacing Semgrep, and includes built-in sandboxing via nono-py to prevent exploitation during analysis. This release emphasizes improved accuracy, reduced false positives, and defense-in-depth against vulnerabilities in the scanner itself.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
GitHub Repo DataDog/malicious-software-packages-dataset Details →
Filename 2026-03-24-litellm-v1.82.7.zip Details →