Threat intel for the open source software supply chain.
OpenSourceMalware is a purpose-built threat intelligence feed for malicious OSS. Not just “Is this malware?” but also “What does it do? What's the payload? Who's behind it? How do I detect it?”
Individuals and organizations use our data to:
- Block malware before it's downloaded
- Catch malware already in the code
- Alert on new threats
- Respond to an incident
- Research adversaries and hunt for threats
Browse our data through an ungated feed or consume it via API to automate security processes. We support:
- Packages (npm, PyPI, Ruby, etc)
- VS Code / OpenVSX extensions
- AI skills
- Containers
- GitHub repos
- Attacker infra / IOCs (IPs, domains, URLs, blockchain addresses, etc)