RL Blog

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

Products & TechnologyJune 26, 2024

New Portal Helps Devs Spot Malicious Open Source Packages

RL's Spectra Assure Community offers free comprehensive risk assessment of more than 5 million npm, PyPi, and RubyGems packages.

Tomislav Peričin, Chief Software Architect & Co-Founder at ReversingLabsTomislav Peričin
FacebookFacebookXX / TwitterLinkedIn

More Blog Posts

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top
LinkedIn
blueskyBluesky
Email Us

Spotting compromises hidden deep in open source- or commercial supply chains is difficult under the best of circumstances. For developers and development teams tasked with achieving aggressive development and release goals — an environment in which software security and integrity are low priorities — the job is even harder. That’s why, today, ReversingLabs introduced a new offering that helps developers to rapidly assess the security and quality of millions of open source packages spread across platforms such as npm, PyPI and RubyGems.

Spectra Assure Community is a tool that enables developers, product security teams, and release managers to scan open source components to identify the best building blocks for their products. Using Spectra’s unique combination of advanced threat detection, comprehensive analysis, and standardized assessments, it helps developers determine whether packages that they wish to use are free from malicious code and supply chain attacks.

Get your free risk assessment of more than 5 million open source packages at secure.software

Mind the Brainleeches! The Value of OSS Threat Intelligence

Spectra Assure Community provides protections against sophisticated supply chain compromises and threats that are becoming far more common on open source package managers. That includes threats like Operation Brainleeches, the July 2023 campaign uncovered by ReversingLabs researchers in which malicious actors published more than a dozen malicious packages to the npm open source repository in support of email phishing campaigns targeting Microsoft 365 users.

As with other campaigns, the Operation Brainleeches packages mimicked legitimate npm modules with large user bases. For example, one of the malicious packages was named jqueryoffline, an obvious reference to the jquery package, which has about 7 million weekly downloads. In all, our researchers found malicious npm packages totaling more than 1,000 downloads associated with the Operation Brainleeches campaign.

The key to spotting this evolving malicious campaign was Spectra Assure’s ability to peer into open source packages and spot suspicious or outright malicious behaviors and content. For example, Spectra Assure flagged HTML code in the DEMO.txt file — a component of the npm package standforusz — that mimicked the login for Microsoft.com and made a call out to the URL of a remote server to which harvested credentials were sent. That warranted further scrutiny by ReversingLabs researchers, who soon uncovered links to the larger Operation Brainleeches campaign.

Rapid, Reproducible OSS Security Analysis

The newly announced Spectra Assure Community portal offers developers key insights into open source software. By leveraging the world’s largest repository of searchable goodware, grayware and malware, it gives developers unparalleled visibility and detection of emerging threats within open source repositories.

In addition, Spectra Assure leverages proprietary, AI-driven complex binary analysis of open source components, embedded artifacts and dependencies for malware, tampering, secrets, vulnerabilities, hardening, and licensing irregularities. This gives development teams an early heads up about unusual changes in the open source and proprietary packages they use.

The benefits of technology like Spectra Assure and the Spectra Assure Community portal are clear. With the help of these new tools, developers and development teams can perform rapid analysis of open source modules and use those to inform selection decisions, boosting productivity. Also, Spectra Assure enables traceable and reproducible security decisions: With comprehensive package analysis and uniform reporting standards, Spectra Assure provides consistent and auditable security decisions.

The benefits of a tool like Spectra Assure are easy to grasp. By incorporating a broad set of security criteria consistently throughout the software lifecycle, development teams are empowered to select the best and most secure open source package version for their project. At the same time, they can more easily avoid packages that have been found to contain malicious components - either now or in the past. That's because Spectra Assure Community not only provides security assessments of the latest open source updates, it lets developers and development teams track the evolution of open source packages over time, documenting past security incidents or compromises in ways that raise the overall security posture of the final application.

OSS Security Intelligence is a Search Away

The Spectra Assure Community portal is publicly available at secure.software. It provides public access to RL analysis of more than 5 million npm, PyPi, and RubyGems packages, with more exciting developments on the way. Developers can start by entering the name of the open source module to find the corresponding RL Assessment. The intuitive report for each component version reveals security quality and allows rapid evaluation of different packages or versions of a specific package.

Check out Spectra Assure Community and use it to find the best building blocks for your next application.

Learn more about Spectra AssureTalk with an expert

Tags:Products & Technology
Tomislav Pericin headshot
spectra assure community landing page

Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for scalable file analysis, Spectra Analyze for malware analysis and threat hunting, and Spectra Intelligence for reputation data and intelligence.

ReversingLabs: The More Powerful, Cost-Effective Alternative to VirusTotalSee Why
Skip to main content
Contact UsSupportLoginBlogCommunity
reversinglabs
ReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseProtect Virtual MachinesIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
EventsRL at RSAC
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu
QR Code Phishing Is Evolving: Here’s How Your Detection Can Keep Up

QR Code Phishing Evolves: How to Keep Up

Here's what you need to know about the rise of quishing — and how your threat hunting team can get out in front of it.

Learn More about QR Code Phishing Evolves: How to Keep Up
QR Code Phishing Evolves: How to Keep Up
Why RL Built Spectra Assure Community

Why RL Built Spectra Assure Community

We set out to help dev and AppSec teams secure the village: OSS dependencies, malware, more. Learn how.

Learn More about Why RL Built Spectra Assure Community
Why RL Built Spectra Assure Community
How a Simple YARA Rule Catches What AV Misses

ClickFix: YARA Rules Catch What AV Misses

Learn about the antivirus detection gap — and how to develop a simple YARA rule using Spectra Analyze.

Learn More about ClickFix: YARA Rules Catch What AV Misses
ClickFix: YARA Rules Catch What AV Misses

How to Examine Polyglot Files with Spectra Analyze

Here's how to assess a sample using Spectra Analyze in your environment — and create a YARA rule.

Learn More about How to Examine Polyglot Files with Spectra Analyze
How to Examine Polyglot Files with Spectra Analyze
Polyglot File Examination with Spectra Analyze