Browse live malware projects
Trojanized package update reached our build servers — need forensic scoping
Supply Chain / Packaged Malware
We suspect our build pipeline was compromised and that artifact-signing or deploy credentials may have been read by malicious code injected into the build. We need a forensic determination of what was exposed, whether any signed artifact is untrustworthy, and a hardened rebuild plan from a known-good base.
Budget: $5,900 - $11,050
Compromised maintainer published a malicious release into our dependency tree
Supply Chain / Packaged Malware
Our build servers ingested a tampered package update before the registry yanked it. We need to know what the payload did, whether build secrets left the environment, and which artifacts may be contaminated. Looking for a researcher to scope blast radius and confirm whether exfiltration actually completed.
Budget: $4,700 - $8,800
Infostealer Outbreak Across Corporate Endpoints — Forensic Triage Needed
Computer / Endpoint Malware
A domain-joined laptop continues to re-establish suspicious outbound connections after reimaging, suggesting persistence the client cannot locate. The engagement covers static and memory-based analysis to find the persistence foothold and reconstruct the intrusion timeline. The output must be clear enough for a non-technical leadership briefing.
Budget: $5,200 - $9,750
Self-Spreading Loader Outbreak: Propagation Graph and Patient-Zero Analysis
Worms & Self-Propagating
Removable USB drives carried a worm onto an isolated production network, and infected machines keep reappearing after cleanup. We need help confirming the propagation mechanism, scoping every affected endpoint, and closing the autorun and trust gaps that allow reinfection.
Budget: $1,300 - $2,400
Botnet Membership Assessment Across a Mid-Size Network
Botnets & C2
A recovered implant resolves an ever-changing list of domains, which suggests a domain-generation algorithm rather than a fixed C2. We want the generation logic reversed, the seed and date dependency identified, and a forward-looking list of likely domains so we can pre-emptively block and monitor them.
Budget: $4,100 - $7,750
iOS Device Showing Unexplained Network Traffic — Mobile Malware Assessment
Mobile Malware
An employee's iPhone enrolled in an unknown MDM profile after tapping a link, and apps now appear and update without consent. We need someone to analyze the configuration profile, identify what it grants the operator, and produce safe removal and re-hardening steps. iOS provisioning-profile experience required.
Budget: $7,050 - $13,200
Magento Checkout Skimmer Removal and Forensic Triage
Website / Web Malware
Our public homepage was replaced with a defacement message for roughly an hour before we restored a backup. We want the original entry vector confirmed, any lingering access removed, and hardening recommendations so it cannot recur.
Budget: $3,950 - $7,450
Extortion Negotiation Risk Assessment and Data-Leak Exposure Review
Ransomware & Extortion
The organization experienced a network-wide encryption event that halted business operations across multiple servers and endpoints. We need a researcher to reconstruct the intrusion timeline, identify the initial access vector, and produce a decryptability assessment with a prioritized recovery roadmap.
Budget: $5,400 - $10,150