Browse live malware projects
AllBotnets & C2Computer / Endpoint MalwareMacro & Document MalwareMobile MalwareRansomware & ExtortionSupply Chain / Packaged MalwareWebsite / Web MalwareWorms & Self-Propagating
Trojanized package update reached our build servers — need forensic scoping
Supply Chain / Packaged Malware
We suspect our build pipeline was compromised and that artifact-signing or deploy credentials may have been read by malicious code injected into the build. We need a forensic determination of what was exposed, whether any signed artifact is untrustworthy, and a hardened rebuild plan from a known-good base.
Budget: $5,900 - $11,050
Compromised maintainer published a malicious release into our dependency tree
Supply Chain / Packaged Malware
Our build servers ingested a tampered package update before the registry yanked it. We need to know what the payload did, whether build secrets left the environment, and which artifacts may be contaminated. Looking for a researcher to scope blast radius and confirm whether exfiltration actually completed.
Budget: $4,700 - $8,800