Browse live malware projects

Trojanized package update reached our build servers — need forensic scoping

Supply Chain / Packaged Malware

We suspect our build pipeline was compromised and that artifact-signing or deploy credentials may have been read by malicious code injected into the build. We need a forensic determination of what was exposed, whether any signed artifact is untrustworthy, and a hardened rebuild plan from a known-good base.

Budget: $5,900 - $11,050

Compromised maintainer published a malicious release into our dependency tree

Supply Chain / Packaged Malware

Our build servers ingested a tampered package update before the registry yanked it. We need to know what the payload did, whether build secrets left the environment, and which artifacts may be contaminated. Looking for a researcher to scope blast radius and confirm whether exfiltration actually completed.

Budget: $4,700 - $8,800