> Has anyone tested general purpose malware detection on supply chains ? Like clamscan
You could use Trivy! /s