Threat intelligence · Vulnetix Research Lab

Malware Campaigns & Threat Actors

Every supply-chain malware campaign we track, and the actors behind them. Each campaign gets an impact-and-mitigations teardown; each actor a motivations-and-tradecraft profile. Where our data is partial, we show the indicators of compromise and say so, nothing is invented.

Block these before they install

684

Campaigns tracked

55,866

Threat actors

336,122

Indicators retained

275,001

Malicious records

Two tiers of campaigns

186 curated campaigns are hand-researched and actor-attributed, each its own story, with a teardown written specifically for it. 498 catalogued campaigns are coordinated malicious-package batches auto-grouped from our 275,001-record malware feed (a shared scope, mass-publish stem, or typosquat family).

Curated campaigns

The hand-researched, actor-attributed campaigns in the Vulnetix malware corpus:

STIX feeds for your own controls

We publish the malicious domains, IPs and URLs from this intelligence as free, machine-readable STIX 2.1 bundles split per ecosystem and refreshed every 15 minutes. Start with the generic DNS and URL bundles, or use the interactive page to pick a registry-specific feed.

Download Generic DNS STIX · Download Generic URLs STIX

Caught after they shipped: block them at the gate

Every indicator above was catalogued after the package shipped. The Vulnetix Package Firewall checks each install against this same malware intelligence, across 25+ registries, before the dependency reaches your build. Where Aikido SafeChain, Socket, JFrog Curation and DevGuard each draw on narrower feeds, Vulnetix aggregates OSSF Malicious Packages, OSV.dev, GitHub Advisory and first-party research into one of the largest de-duplicated malware corpora in the industry, then adds Safe Harbour autofix.

Block these before they install →