Chasing Next
Explore LessonsAI UpdatesBlogAbout
Log inFor TeamsStart for Free
Chasing Next

Learn AI by doing.

Start for FreeFor TeamsFree AI GuideAboutFAQUpdatesBlog
Sign UpSign InSupport
2026 Moonswell Marketing LLC·Terms·Privacy··
All Updates
PerplexityPerplexityfeature
May 22, 2026·Source

Bumblebee

Open-source scanner that checks developer laptops for risky packages, extensions, and AI tool configs without triggering anything malicious.

Details

  • Covers npm, pnpm, Yarn, Bun, PyPI, Go modules, RubyGems, Composer, MCP server configs, editor extensions, and browser extensions
  • Three scan profiles: baseline for routine checks, project for specific repos, deep for active incident response
  • Read-only by design: never runs install scripts, package managers, or lifecycle hooks, so scanning a compromised machine cannot trigger the attack
  • Written in Go with zero non-stdlib dependencies and published as free open source on GitHub

Best for

Security and platform teams who need to know which developer laptops have vulnerable packages installed

When to use it

A supply-chain compromise drops and you need to sweep every developer machine fast without triggering the attack itself

Who benefits

Security teams and platform engineers responsible for endpoint exposure during incidents

More from Perplexity

All updates
model
pplx-embed-v2-late
model
pplx-decider v1.1
api
Perplexity Decisions API
Chasing Next

Staying informed is great. Staying ahead is better.

Pick a topic and leave with something you created.

Start for FreeBring to Your Team

Get new module drops and weekly AI strategy.