Threat intelligence · Vulnetix Research Lab

Malware Campaigns & Threat Actors

Every supply-chain malware campaign we track, and the actors behind them. Each campaign gets an impact-and-mitigations teardown; each actor a motivations-and-tradecraft profile. Where our data is partial, we show the indicators of compromise and say so — nothing is invented.

Block these before they install

684

Campaigns tracked

55,866

Threat actors

336,122

Indicators retained

275,001

Malicious records

Two tiers of campaigns

186 curated campaigns are hand-researched and actor-attributed — each its own story, with a teardown written specifically for it. 498 catalogued campaigns are coordinated malicious-package batches auto-grouped from our 275,001-record malware feed (a shared scope, mass-publish stem, or typosquat family).

Curated campaigns

The hand-researched, actor-attributed campaigns in the Vulnetix malware corpus:

STIX feeds for your own controls

We publish the malicious domains, IPs and URLs from this intelligence as free, machine-readable STIX 2.1 bundles split per ecosystem and refreshed every 15 minutes. Start with the generic DNS and URL bundles, or use the interactive page to pick a registry-specific feed.

Download Generic DNS STIX · Download Generic URLs STIX

Caught after they shipped — block them at the gate

Every indicator above was catalogued after the package shipped. The Vulnetix Package Firewall checks each install against this same malware intelligence, across 25+ registries, before the dependency reaches your build. Where Aikido SafeChain, Socket, JFrog Curation and DevGuard each draw on narrower feeds, Vulnetix aggregates OSSF Malicious Packages, OSV.dev, GitHub Advisory and first-party research into one of the largest de-duplicated malware corpora in the industry — then adds Safe Harbour autofix.

Block these before they install →