Phylum Research Team

Phylum Research Team

Hackers, Data Scientists, and Engineers responsible for the identification and takedown of software supply chain attackers.

The Dependency Network Shows the Complexity of the Software Ecosystem

The open-source software ecosystem as a complex system It can be complicated to develop software in the open-source software ecosystem. No doubt! But I believe we are increasingly working not just in a complicated line of

Malicious Open-Source Package Authors are Bad, and Should Feel Bad

With the numerous publications around malware findings in open source, it is no secret that malware is pervasive. What may come as a surprise (but really shouldn’t) is that most of this reported malware is

Malware Targeting dYdX Crypto Exchange

Shortly before 12:00 PM UTC on September 23, 2022, our platform alerted us to a malicious package publication for packages owned by dYdX. It currently remains unclear how these packages became compromised. What is clear,

Achieve Policy Automation in Open-Source Software

Phylum provides tools to proactively manage policy and allows organizations to create custom options to moderate issues stemming from open-source packages.

NPM Malware Targeting HubSpot’s Bucky Client

Our risk analysis platform recently alerted us to a malicious package in the NPM ecosystem targeting Bucky Client, a project owned by HubSpot. It is currently averaging around 600 installations per week. The package in question