Nextron Research monitors open-source package registries and extension marketplaces for malicious artifacts, using THOR Thunderstorm for deterministic scanning and LLM triage to reduce analyst workload. It has uncovered malicious Go, PHP, and npm packages, including credential-stealing RATs and 2FA bypass code.