The repository has collected over 10,000 malicious pypi packages. This dataset is the work of the ASE 2023 paper "An Empirical Study of Malicious Code In PyPI Ecosystem". Of course, we will continue to expand the dataset. Latest update time: 21 July. 2026
☆128Jul 21, 2026Updated last week
Alternatives and similar repositories for pypi_malregistry
Users that are interested in pypi_malregistry are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆17Jul 25, 2024Updated 2 years ago
- The Artifacts for ICSE 2023 paper: Bad Snakes: Understanding and Improving Python Package Index Malware Scanning☆13Feb 8, 2026Updated 5 months ago
- An open-source dataset of malicious software packages found in the wild, 100% vetted by humans.☆368Updated this week
- Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages☆140Oct 5, 2022Updated 3 years ago
- Artifact accompanying our ICSE '22 paper "Practical Automated Detection of Malicious npm Packages"☆47Jan 25, 2022Updated 4 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A fork of Bandit tool with patterns to identifying malicious python code.☆31Sep 1, 2022Updated 3 years ago
- A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerabilit…☆587Updated this week
- Automatically scan new pypi packages for potentially malicious code☆31Mar 24, 2024Updated 2 years ago
- GuardDog is a CLI tool to Identify malicious PyPI and npm packages☆1,168Updated this week
- This repository contains a list of papers about software supply chain☆29May 22, 2024Updated 2 years ago
- Modular static malicious JavaScript detection system☆76Jan 18, 2021Updated 5 years ago
- ☆31May 1, 2025Updated last year
- Resources for our ICSE'24 poster: Prompt-Enhanced Software Vulnerability Detection Using ChatGPT.☆25May 8, 2024Updated 2 years ago
- A dataset of software supply chain compromises. Please help us maintain it!☆130Sep 16, 2022Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- YASA-UAST is an intermediate representation structure for multi-language program analysis. The UAST-Parser parses code from different pro…☆86Jul 6, 2026Updated 3 weeks ago
- Mininode is a CLI tool to reduce the attack surface of the Node.js applications by using static analysis.☆21Apr 11, 2023Updated 3 years ago
- Automated Exploit Generation for Node.js Packages☆20Updated this week
- TensorFlow API analysis tool and malicious model detection tool☆41May 27, 2025Updated last year
- YASA is an open-source static program analysis project. Its core innovation lies in a unified intermediate representation called UAST, d…☆304Updated this week
- archives for Tongji CTF 2017☆10Oct 25, 2023Updated 2 years ago
- 使用 Docker 一键构建 JDK 源码的 CodeQL 数据库,方便使用 CodeQL 查找 JDK 中的数据。☆27May 14, 2025Updated last year
- Code and dataset for paper C4: Contrastive Cross-Language Code Clone Detection☆30May 24, 2022Updated 4 years ago
- ☆13Jan 22, 2024Updated 2 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- PyPI malware packages☆59Dec 12, 2018Updated 7 years ago
- A CVE Data MCP using the CVE.ORG API☆15Jun 4, 2025Updated last year
- Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD …☆208Updated this week
- Bundle of security analysis scripts for keras tensorflow models☆16Apr 15, 2024Updated 2 years ago
- 安全升级jar包 时,辅助检测Java Archive (JAR) 包之间兼容性,各类符号引用的存在检测,包括方法、方法签名、字段定义和引用、类引用等等☆15Jul 7, 2024Updated 2 years ago
- AFL++ using the Ball-Larus path profiling algorithm for coverage feedback☆15Oct 31, 2022Updated 3 years ago
- ODGen is a JavaScript Static Analysis tool to detect multiple types of vulnerabilities in Node.js packages.☆169Jan 29, 2024Updated 2 years ago
- ☆13Jun 26, 2023Updated 3 years ago
- JEST: N+1-version Differential Testing of Both JavaScript Engines☆14Jun 1, 2021Updated 5 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- UpCy automatically finds compatible updates for Maven dependencies.☆12Feb 8, 2026Updated 5 months ago
- ☆20Nov 7, 2023Updated 2 years ago
- A novel and interpretable ML-based approach to classify malware with high accuracy and explain the classification result meanwhile.☆29Nov 23, 2022Updated 3 years ago
- Debug pwn in docker, no need for virtual machines☆38Oct 10, 2025Updated 9 months ago
- Scan pypi for typosquatting☆37Jan 23, 2023Updated 3 years ago
- 🪲 A list of malware and benign datasets for malware research☆46Jan 31, 2026Updated 5 months ago
- ☆15Apr 17, 2024Updated 2 years ago