Bumblebee supply chain scanner

Your developer laptop finally has a supply-chain scanner - Perplexity open-sourced Bumblebee

The problem On May 20, 2026, a malicious VS Code extension compromised over 3,800 GitHub repositories before anyone noticed. The attack vector was not a zero-day. It was a package that developers installed voluntarily, trusted by default, sitting quietly on their laptops. Supply-chain attacks have shifted. The target is no longer just the CI/CD pipeline or the production build. It is the developer machine itself - the local environment where code is written, where extensions are installed, where AI agent configs live. ...

May 24, 2026 · 4 min · Kamer Vishi