From single pull requests to full software packages: Detecting malicious code at scale
Datadog | The Monitor blog

From single pull requests to full software packages: Detecting malicious code at scale


Summary

The article describes the expansion of BewAIre, an LLM-based security system, from analyzing pull requests to scanning entire dependency packages for malicious code. The updated system utilizes a two-stage pipeline consisting of an inexpensive "filter" phase for rapid screening, followed by an agentic investigation loop that uses high-powered models and external tools to deep-dive into suspicious flags. This approach significantly increased detection accuracy to 99.86% and eliminated false positives while maintaining operational efficiency and cost-effectiveness.
Read the Original Article

This article originally appeared on Datadog | The Monitor blog.

Read Full Article on Original Site

Popular from Datadog | The Monitor blog

1
DASH 2026: Guide to Datadog’s newest announcements
DASH 2026: Guide to Datadog’s newest announcements

Datadog | The Monitor blog Jun 9, 2026 206 views

2
DASH 2026 Harnessing AI: Guide to Datadog’s newest announcements
DASH 2026 Harnessing AI: Guide to Datadog’s newest announcements

Datadog | The Monitor blog Jun 9, 2026 178 views

3
Datadog LLM Observability natively supports OpenTelemetry GenAI Semantic Conventions
4
Introducing Bits AI Dev Agent for Code Security
Introducing Bits AI Dev Agent for Code Security

Datadog | The Monitor blog Mar 26, 2026 107 views