Perplexity just open-sourced Bumblebee, a free tool that runs quietly on your laptop and scans for malicious code, sketchy browser plugins, and AI tools silently leaking your credentials.
Context: for the past 6 months, attackers have been poisoning open-source packages that developers install daily. Get one bad package and they own everything you touch, including your Claude Code, Cursor, and Codex API keys.
Most security tools protect the app. Bumblebee protects the builder.
Independently verified clean. Worth installing if you ship anything with AI.
Today we're open-sourcing Bumblebee, a read-only scanner for macOS and Linux.
It checks developer machines for risky packages, extensions, and AI tool configs.
Connected to Computer, it can trigger deeper scans whenever a new supply-chain risk emerges.
github.com/perplexityai/bumb…