Hey, I built this thing called InstallScope and wanted to share.
It watches what happens at the syscall level when you install a package: file writes, network calls, spawned processes, whether it touches your credentials. Then it puts a report on the PR so you can actually see what a dependency update does before merging it.
Real example here, on an actual PR in a demo repo: https://github.com/mukti-sys/installscope-demo/pull/1. bcrypt gets a 10/100 because it spawns node-gyp-build, which is fine, that's just a native build step, but it looks scary until you check.
The reasoning: npm audit only knows about CVEs that already got published, provenance tells you who signed the package but not what the install script does, and static scanners are just guessing without running anything. Install scripts get your full user permissions, so I wanted actual evidence instead of a guess.
I recorded 250 installs across 50 popular npm packages (200 version-to-version pairs) on GitHub Actions runners, about 840k syscalls total. Every single install hit the network and read ~/.npmrc, but comparing versions, nothing added a new external endpoint or new credential read. Only 3 packages added new spawned processes: bcrypt, sqlite3, protobufjs. All three were normal native builds. So the interesting signal isn't "does it do X," it's "did it start doing X that it wasn't doing before." Small caveat: most of these events (99.8%) are just filesystem writes, so the interesting stuff is a much smaller sample.
Being upfront: this was all benign packages, I haven't run it against actual malware yet. It uses strace under the hood. There's an eBPF option too but it misses some stuff (credential reads, DNS), doesn't catch io_uring, and I haven't benchmarked the overhead.
Takes like a minute to try, doesn't execute any install scripts, works on Linux/Mac/Windows:
git clone https://github.com/mukti-sys/InstallScope
cd InstallScope
cargo run -p installscope — report corpus/demo/critical.jsonl
(the sample file is fake/synthetic btw, just shows you the report format, actual live recording needs Linux or WSL2)
Wrote up the whole experiment here if you want details: https://github.com/mukti-sys/InstallScope/blob/main/docs/blog/the-840k-syscall-experiment.md
Curious what people think of the rule catalog, and whether something like this would actually fit into your PR review flow.
Source: r/rust · by /u/No_Source2592