AI native security
Trust what your AI builds.
No blind spots.
We provide your assistant with the most accurate data on open source risks.
Risk checks in your IDE, your CI/CD, and your AI tools — all free. Take what fits your workflow.
Our threat analysts dissect real open-source attacks. Straight from the front lines.

Apr 29, 2026
North Korean malware infiltrated a trading agent - showcasing both the use of LLMs in malware development and as infection vectors.

Apr 9, 2026
An attack targeting crypto developers has been respawned — with an LLC and new techniques to hide malware.

Mar 24, 2026
The final-stage malware in the Ghost campaign is a RAT designed to steal crypto wallets and sensitive data.

Feb 12, 2026
More-in-depth technical analysis of the packages involved in the "graphalgo" campaign.

Feb 11, 2026
A new branch of a fake job recruitment campaign, dubbed "graphalgo", is targeting developers with a RAT.

Dec 17, 2025
Malicious NuGet package targeting crypto wallets and OAuth tokens to steal funds.

Dec 10, 2025
RL has discovered 19 malicious extensions on VSCode Marketplace - the majority containing a malicious file posing as a PNG.

Dec 9, 2025
RL automated detection system has detected the new wave of Shai-Hulud worm compromising popular npm packages with cloud token-stealing malware.

Nov 26, 2025
Bootstrap scripts for zc.buildout that install the package distribute fetch and execute an installation script from python-distribute[.]org — a legacy domain that is now available for sale.

Nov 4, 2025
PowerShell clobbering combined with autoloading and dynamic modules in the global scope allows modules to register commands that can take precedence over those registered by the system, resulting in command hijacking.

Sep 16, 2025
RL researchers have detected the first self-replicating worm compromising popular npm packages with cloud token-stealing malware.

Jul 8, 2025
Supply chain attack targeting a VSCode marketplace extension via a malicious pull request.

May 23, 2025
Malicious PyPI packages contain fully functional infostealer code inside PyTorch models that get loaded from package initialization scripts.

May 15, 2025
Sophisticated, malicious package uses Global Socket Toolkit as a backdoor in an ongoing campaign likely linked to the Ukrainian hacktivist gang DumpForums.

May 13, 2025
New Python package revives the name of a malicious module to steal source code and secrets from blockchain developers’ machines.

Apr 3, 2025
RL automated ML detection system detected 2 malicious PyPI packages targeting users of popular bitcoinlib library with more than 1 million downloads.

Dec 9, 2024
Popular AI library with 60 million downloads compromised by exploiting GitHub actions vulnerability. The compromised PyPI package delivers downloader code.

Nov 28, 2024
ReversingLabs’ machine learning-based threat hunting system detects malicious code in legitimate looking package engineered to compromise crypto currency wallets.

Jul 11, 2024
Malicious NuGet packages found impersonating legit packages using homoglyphs and injecting malicious functionality using IL weaving.

Mar 26, 2024
Suspicious package that demonstrates how tiny can the line between industrial espionage and unconventional feature implementation be.

Apr 16, 2020
“Jim Carrey” and “Peter Gibbons” impersonators join in a barrage of typosquatting malware on RubyGems targeting software repository users. The malicious code was designed to redirect cryptocurrency transactions.
Everything Community offers is free, the account just unlocks more of it.
No account needed
Free account
Free forever. Two clicks. No credit card.
Unlock everythingSecure everywhere you build: from your AI assistant to your release pipeline.
Secure your AI development
Tools and integrations
Every package scanned for malware, tampering, vulnerabilities and other risks
Developer tools
ReversingLabs Threat Research team protects Open Source communities from threats hidden in the software supply chain. Using the Spectra Assure platform capabilities, our team helps with removing malicious code from package repositories. Threat intelligence found on this website is shared back with the Open Source community.
We contribute the lists of malicious packages we discover to the OSSF Malicious Packages Database.