> For the complete documentation index, see [llms.txt](https://breachtrace.gitbook.io/vulnkeeper/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://breachtrace.gitbook.io/vulnkeeper/chapter-e/13-13-malicious-package-supply-chain-compromise-and-package-reputation-sources.md).

# 13. Malicious package, supply-chain compromise & package reputation sources

## 13.1 Malicious package databases

<table><thead><tr><th width="96.3203125" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>OpenSSF Malicious Packages repository</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/ossf/malicious-packages">github.com/ossf/malicious-packages</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Public malicious package reports consumable via OSV format.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Covers malicious packages, which may not be CVEs.</td></tr><tr><td align="right">2</td><td><strong>OpenSSF Malicious Packages announcement</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://openssf.org/blog/2023/10/12/introducing-openssfs-malicious-packages-repository/">openssf.org/blog/2023/10/12/introducing-openssfs-malicious- packages-repository</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Explains the public DB for malicious package reports.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Context source, not the primary data feed.</td></tr><tr><td align="right">3</td><td><strong>OpenSSF Package Analysis</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://openssf.org/package-analysis/">openssf.org/package-analysis</a><br><br><strong><code>Access / Cost</code>:</strong> Free public project info</td><td><strong><code>Relevance</code>:</strong> Detects malicious package behavior &#x26; informs package consumers.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Behavioral analysis may surface packages before CVE/advisory assignment.</td></tr><tr><td align="right">4</td><td><strong>OpenSSF Package Analysis GitHub</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/ossf/package-analysis">github.com/ossf/package-analysis</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Open-source package analysis system.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for detection logic &#x26; behavioral signal review.</td></tr><tr><td align="right">5</td><td><strong>OpenSSF Package Feeds</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/ossf/package-feeds">github.com/ossf/package-feeds</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Package ecosystem feed monitoring.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for observing new packages in ecosystems.</td></tr><tr><td align="right">6</td><td><strong>GitHub malware advisories</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/advisories?query=type%3Amalware">github.com/advisories?query=type%3Amalware</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> GitHub malware advisories across ecosystems.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Treat as supply-chain compromise data, not conventional vuln data.</td></tr><tr><td align="right">7</td><td>npm malware advisories via GitHub</td><td><a href="https://github.com/advisories?query=ecosystem%3Anpm+type%3Amalware">github.com/advisories?query=ecosystem%3Anpm+type%3Amalware</a></td></tr><tr><td align="right">8</td><td>PyPI malware advisories via GitHub</td><td><a href="https://github.com/advisories?query=ecosystem%3Apip+type%3Amalware">github.com/advisories?query=ecosystem%3Apip+type%3Amalware</a></td></tr><tr><td align="right">9</td><td>Socket.dev blog</td><td><a href="https://socket.dev/blog">socket.dev/blog</a></td></tr><tr><td align="right">10</td><td>Snyk vulnerability database</td><td><a href="https://security.snyk.io/">security.snyk.io</a></td></tr><tr><td align="right">11</td><td>Sonatype OSS Index</td><td><a href="https://ossindex.sonatype.org/">ossindex.sonatype.org</a></td></tr><tr><td align="right">12</td><td>Sonatype vulnerability database</td><td><a href="https://sonatype.com/resources/vulnerability-database">sonatype.com/resources/vulnerability-database</a></td></tr><tr><td align="right">13</td><td>Phylum research</td><td><a href="https://blog.phylum.io/">blog.phylum.io</a></td></tr><tr><td align="right">14</td><td>ReversingLabs threat research</td><td><a href="https://www.reversinglabs.com/blog">www.reversinglabs.com/blog</a></td></tr><tr><td align="right">15</td><td>Checkmarx supply-chain research</td><td><a href="https://checkmarx.com/blog/">checkmarx.com/blog</a></td></tr></tbody></table>

## 13.2 Package reputation / dependency health

<table><thead><tr><th width="92.15625" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>OpenSSF Scorecard</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/ossf/scorecard">github.com/ossf/scorecard</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Scores open-source project security practices.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful as dependency risk signal, not vulnerability proof.</td></tr><tr><td align="right">2</td><td><strong>OpenSSF Scorecard API</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://api.securityscorecards.dev/">api.securityscorecards.dev</a><br><br><strong><code>Access / Cost</code>:</strong> Free public API subject to service limits</td><td><strong><code>Relevance</code>:</strong> API for Scorecard results.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Use with timestamped results because scores change over time.</td></tr><tr><td align="right">3</td><td><strong>OpenSSF Best Practices Badge</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.bestpractices.dev/">www.bestpractices.dev</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Project best-practices badge program.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful project maturity signal, not vulnerability evidence.</td></tr><tr><td align="right">4</td><td><strong>deps.dev</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://deps.dev/">deps.dev</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Dependency metadata, transitive dependencies, security signals.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for dependency graphing &#x26; package metadata.</td></tr><tr><td align="right">5</td><td><strong>OpenSSF GUAC</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://guac.sh/">guac.sh</a><br><br><strong><code>Access / Cost</code>:</strong> Free public / open-source project</td><td><strong><code>Relevance</code>:</strong> Graph for software supply- chain metadata.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for correlating SBOMs, attestations, vulnerabilities, &#x26; provenance.</td></tr><tr><td align="right">6</td><td><strong>GUAC GitHub</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/guacsec/guac">github.com/guacsec/guac</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> GUAC implementation repository.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Reference architecture for supply-chain knowledge graphs.</td></tr><tr><td align="right">7</td><td><strong>Sigstore</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.sigstore.dev/">www.sigstore.dev</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public infrastructure</td><td><strong><code>Relevance</code>:</strong> Signing &#x26; verification for software artifacts.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Helps assess provenance &#x26; tamper resistance.</td></tr><tr><td align="right">8</td><td><strong>Rekor transparency log</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://docs.sigstore.dev/logging/overview/">docs.sigstore.dev/logging/overview</a><br><br><strong><code>Access / Cost</code>:</strong> Free public docs / public transparency log</td><td><strong><code>Relevance</code>:</strong> Transparency log for signed artifacts.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for provenance verification &#x26; audit trails.</td></tr><tr><td align="right">9</td><td><strong>SLSA framework</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://slsa.dev/">slsa.dev</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open standard</td><td><strong><code>Relevance</code>:</strong> Supply-chain Levels for Software Artifacts.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Helps assess build integrity &#x26; supply-chain hardening.</td></tr></tbody></table>

## Discussion

This chapter section keeps the latest table structure, source titles, access/cost fields, relevance notes, & operational notes from the source inventory. Review the table entries as ingestion candidates, then validate source freshness, licensing, authentication requirements, & link-check behavior before production use.

***

#### [Back to Index](/vulnkeeper/index.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://breachtrace.gitbook.io/vulnkeeper/chapter-e/13-13-malicious-package-supply-chain-compromise-and-package-reputation-sources.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
