discovered 03 Aug 2026
hexora
→ View on GitHubHexora is a static analysis tool for Python code that identifies malicious patterns and harmful constructs through a combination of rule-based analysis and machine learning scoring. Its primary use cases include auditing project dependencies for supply chain vulnerabilities, detecting malicious scripts on public platforms, and analyzing compromise indicators from previous security incidents. Notable features include high-confidence scoring for detected threats, customizable audit options (such as excluding specific rule codes), and the ability to audit entire directories or virtual environments.