Enterprise security and monitoring for developers. Auto-restart, threat detection, pkl inspector, supply chain protection.
Project description
stillrunning
Supply chain security for teams without security teams.
pip install stillrunning
What it does
- Blocks malicious packages before they run — intercepts npm/pip install, checks against live threat feed
- Catches what AV misses — AST analysis, entropy detection, pickle inspection without execution
- Learns your environment — auto-whitelists your processes, alerts on anomalies
- Updates itself — syncs blocklist every 60 minutes from 6 threat intel sources
The attack it was built for
In 2026, North Korean state hackers published WAVESHAPER.V2 — 1,700+ malicious packages across npm and PyPI. Credential stealers disguised as logging utilities. Traditional AV found nothing. Enterprise tools cost $50k/year.
stillrunning catches it at install time, before it ever runs.
Live proof
stillrunning.io/threats — real-time intercept dashboard.
Not a demo. Every package check, every block, every threat advisory — live.
Quick start
pip install stillrunning
stillrunning --setup
The setup wizard detects your running processes, configures monitoring, and connects to the live threat feed. Takes 3 minutes.
Stats
- 33+ malicious packages in blocklist
- 817,000+ alerts suppressed by guard daemon
- 0 incidents on protected machines
- 6 sources: CISA, OSV.dev, NVD, GitHub Security, npm advisories, Snyk
- Updated hourly
Pricing
| Tier | Price | What you get |
|---|---|---|
| Open Source | Free | Core tools, local scanning |
| Personal | $9/mo | Live threat rules, guard daemon |
| Basic | $29/mo | + intercept, Telegram alerts |
| AI | $49/mo | + crash diagnosis, auto-fix suggestions |
| Enterprise | $499/mo | SSO, SIEM, SOC2 compliance reports |
Links
- stillrunning.io — homepage
- stillrunning.io/threats — live threat dashboard
- stillrunning.io/docs — API docs
- @bit_bot9000 — updates
License
MIT License
Patent Pending — US Provisional Application filed April 12, 2026
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file stillrunning-1.9.0.tar.gz.
File metadata
- Download URL: stillrunning-1.9.0.tar.gz
- Upload date:
- Size: 50.9 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.12.3
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b4f31ae9a6551e660fb24fbb2513d60f99a4def660fefebacdb88ce5e38b5096
|
|
| MD5 |
c22e2ee78cdc04a26319d0fd0d438249
|
|
| BLAKE2b-256 |
bd5c3dab596ddb5ee44842be6c02f18955c09f9f69843dfaf694c7c046f24073
|
File details
Details for the file stillrunning-1.9.0-py3-none-any.whl.
File metadata
- Download URL: stillrunning-1.9.0-py3-none-any.whl
- Upload date:
- Size: 53.6 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.12.3
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
0611de1a0a433807f72d3f41510ddd30f1c86a426be4bdc0f309e04b57a67caa
|
|
| MD5 |
831eb7a5dead1e85b9bb5cd6417dd802
|
|
| BLAKE2b-256 |
1dfea0fa6dca359810e1e322e72be8338914b924a4a504db6fc36526778a90cf
|