Malicious Package Detection

Stop open source malware before it runs

Open source malware is now its own category of supply chain risk, and AI coding agents install dependencies faster than any human can review. Malicious Package Detection scans every package across the IDE, CI, and your existing applications — catching malware public feeds miss, with expert verification from the Endor Labs security research team.
Loved by security teams, painless for developers at:

How Malicious Package Detection works

Catch malware that public feeds and CVE scanners miss
Roughly 40% of known malicious packages aren't available through public registries, and malware has no CVE — so advisory-matching scanners never see it. Malicious Package Detection scans against 150+ signals and routes unclear findings to Endor Labs researchers for verification.
Stop AI agents from installing malicious packages autonomously
AI agents install dependencies between an LLM suggestion and the next prompt, and install scripts execute immediately — so a bad suggestion can compromise a workstation before anyone reviews it. Detection runs in the IDE before the install script ever runs.
Cut incident response time when the next campaign breaks
When a campaign like Shai-Hulud hits the news, teams can spend days hunting through repositories and lockfiles to confirm exposure. Malicious Package Detection answers 'are we affected?' across every application in minutes.
“Endor Labs' unique reachability-based analysis and native integrations into our agentic software development stack keep our developers focused on rapidly finding and fixing real risks in the SDLC, so we ship faster with confidence.”
Sunil Agrawal Photo
Sunil Agrawal
CISO, Glean
Malware intelligence
Scan every package against 150+ signals and verify unclear findings with human researchers.
Scan every package against 150+ signals across 4.5M+ open source dependencies.
Catch typosquatting, dependency confusion, obfuscated payloads, and code split across files that public feeds miss.
Route unclear findings to the Endor Labs security research team for human verification, so you act on confirmed threats.
Learn more
Pre-install detection
Block malicious packages before a developer or AI agent ever runs the install.
Block known malicious packages before an AI coding agent or developer runs the install script.
Integrate with Cursor hooks and other IDE-level controls to intercept dependencies at the moment of risk.
Apply the same policy to AI agents and humans, so AI adoption doesn't become a path around your controls.
Learn more
Campaign response
Confirm or rule out exposure across every application in minutes.
Confirm or rule out exposure to a new malware disclosure across every application in minutes, not days.
Search the package inventory of every project and SBOM for a specific malicious version the moment it's published.
Build a durable malware program with policies for cooldown periods, unpinned dependencies, and unused code.
Learn more
Flowchart showing integration paths from GitHub, GitLab, and PHP to Slack and Microsoft platforms, with a C# icon connected to Slack.

Your Tools, Your Languages
All Secured

Learn how Endor Labs fits into your ecosystem.
Flow diagram connecting software development tools and platforms including .NET, JetBrains, GitHub, Google, and Vercel.

FAQs

How is malware different from a vulnerability?

A vulnerability is a flaw in legitimate code with a CVE and a patch window; malware is malicious from day one, has no CVE, and can execute the moment you run install. That's why advisory-matching scanners miss it and why detection has to happen before install.

Why aren't public malware feeds enough?

Research shows roughly 40% of known malicious packages aren't available through public registries, and registry takedowns lag the attack. Malicious Package Detection covers threats removed from or not yet in public feeds, scanning against 150+ signals.

Does it cover AI coding agents?

Yes. Detection runs in the IDE and integrates with Cursor hooks and other controls to intercept a package before an AI agent or developer runs the install script — applying the same policy to agents and humans.

How do you keep false positives from overwhelming us?

Unclear findings are routed to the Endor Labs security research team for human verification, so alerts represent confirmed threats and engineering trusts them enough to act.

How fast can we tell if we're exposed to a new campaign?

You can confirm or rule out exposure across every application in minutes by searching the package inventory of every project and SBOM for the malicious version, instead of manually hunting through repositories for days.

Where does it run?

In the IDE before an AI agent or developer installs, in CI before a build ships, and across the package inventory of every existing application.

Code without compromise