Phylum Research Team
Hackers, Data Scientists, and Engineers responsible for the identification and takedown of software supply chain attackers.
The open-source software ecosystem as a complex system
It can be complicated to develop software in the open-source software ecosystem. No doubt! But I believe we are increasingly working not just in a complicated line of
Malicious Open-Source Package Authors are Bad, and Should Feel Bad
With the numerous publications around malware findings in open source, it is no secret that malware is pervasive. What may come as a surprise (but really shouldn’t) is that most of this reported malware is
Malware Targeting dYdX Crypto Exchange
Shortly before 12:00 PM UTC on September 23, 2022, our platform alerted us to a malicious package publication for packages owned by dYdX. It currently remains unclear how these packages became compromised. What is clear,
Achieve Policy Automation in Open-Source Software
Phylum provides tools to proactively manage policy and allows organizations to create custom options to moderate issues stemming from open-source packages.
NPM Malware Targeting HubSpot’s Bucky Client
Our risk analysis platform recently alerted us to a malicious package in the NPM ecosystem targeting Bucky Client, a project owned by HubSpot. It is currently averaging around 600 installations per week.
The package in question