Use cases

Ways to use the feed

OpenSourceMalware's APIs are a flexible way to get intel to the right people at the right time. Click your use case to learn what you can do with our data.

Get API

01 · USE CASE

Block malware before it's downloaded

Malware isn't like vulnerabilities: once it's on a dev machine, you can assume compromise.

That's why development and AppSec teams integrate OpenSourceMalware's feed into proactive controls.

PATTERN · 01

AI code assistant

In agentic environments especially, a malicious dependency suggestion can be installed as fast as a legitimate one. Providing the assistant with context from OpenSourceMalware gives you a lightweight checkpoint without changing how developers work.

PATTERN · 02

Artifact registry

Private registries sit between your developers and the public registries. Wire in the OpenSourceMalware threat database and the proxy can reject a known-malicious package version before it reaches a dev machine. Safe versions of the same package pass through; only the specific flagged version is blocked.

PATTERN · 03

Package firewall

Dedicated package firewall products let you plug in external threat feeds alongside their own detection. Connecting OpenSourceMalware means these tools block on confirmed human-verified malware.

02 · USE CASE

Catch malware already in your code

Sometimes malware reaches your pipelines or even production.

The fix is straightforward: cross-reference your software inventory against the OpenSourceMalware database. Any confirmed threat comes back with version-level detail, so you know exactly which versions are malicious.

PATTERN · 01

SBOM

If you're generating SBOMs, parse out the package/version pairs and check them against our feed. Run this in CI/CD before promoting a build, on a schedule against production inventories, or on-demand during an incident to scope exposure fast.

PATTERN · 02

Build your own scanner

For teams checking large inventories, OpenSourceMalware supports maintaining a local copy of the threat database. Check against the local mirror first and only hit the API for package/version pairs you haven't seen before.

PATTERN · 03

Using a third-party scanner?

If your SCA or malware scanning tool needs better quality data, ask your vendor about integrating with OpenSourceMalware. Bring your own API key or we can work with security vendors on data licensing and OEM integrations.

03 · USE CASE

Alert on new threats

Once malware has executed, the IOCs it leaves behind become the signal.

OpenSourceMalware surfaces these IOCs (C2 domains, exfiltration endpoints, file hashes) for malicious assets, making them available to detection tools that watch your network and endpoint telemetry.

PATTERN · 01

SIEM

Feed OpenSourceMalware IOCs into your SIEM as a threat intel source. When a C2 domain or exfiltration endpoint observed in a confirmed malware campaign appears in your network logs, the SIEM fires an alert. Without that IOC feed, the connection to a malware campaign is invisible.

PATTERN · 02

SOAR

Every confirmed supply chain threat includes the exact package, malicious versions, and associated IOCs. Your SOAR playbook can use that to query your internal dependency inventory, identify affected systems, calculate blast radius, and route to the right responder with the precise indicators to hunt — compressing the window from detection to containment.

PATTERN · 03

Native alerts

OpenSourceMalware's built-in alert system lets you configure notifications, without building custom integrations. Monitor what you care about, including specific packages, publishers, or keywords.

04 · USE CASE

Respond to an incident

When malware executes, every minute without answers is a minute of uncontrolled damage.

The questions are immediate: what did it do, who is behind it, how far did it spread, and what do you tell leadership? OpenSourceMalware gives you the payload context, IOCs, and actor attribution you need to answer the hard questions fast.

PATTERN · 01

Scope your exposure

Cross-reference the confirmed malicious package against your software inventory to identify every system, pipeline, or build that consumed it. Version-level detail means you know exactly what was exposed and what wasn't.

PATTERN · 02

Hunt for activity in your environment

OpenSourceMalware surfaces the IOCs associated with every confirmed malicious package: C2 domains, exfiltration endpoints, file hashes. Feed these into your SIEM or EDR to find out whether the malware executed and what it touched.

PATTERN · 03

Brief leadership and legal

Threat actor profiles and campaign context let you characterize the incident with confidence rather than “we don't know who did this.” Enterprise accounts can request a structured intelligence report suitable for legal counsel, your cyber insurer, or a CISO briefing.

05 · USE CASE

Research adversaries and hunt for threats

Software supply chain malware is an intelligence gap in most CTI programs.

OpenSourceMalware gives analysts and threat hunters a dedicated, structured source for campaign data, actor profiles, and infrastructure connections across the supply chain.

PATTERN · 01

Threat intelligence platform

OpenSourceMalware integrates via REST API, STIX, and RSS. Pull confirmed campaigns, threat actor profiles, and IOCs into the platform where your team manages other intelligence requirements.

PATTERN · 02

Proactive hunting

Use OpenSourceMalware campaign and infrastructure data to form hypotheses and hunt in your own environment before an alert fires. Which actors are active in your ecosystems? Which campaigns share infrastructure with threats you've already seen?

PATTERN · 03

Adversary research

Track confirmed threat actors, their tooling, and how their campaigns evolve over time. Cross-reference with your own collection to build richer profiles and sharpen your threat model.