Company intelligence
Ossprey Security
Securing your open source supply chain
About Ossprey Security
Ossprey Security helps teams stop malicious open-source packages before they land in production. Open source is the backbone of modern software, and it’s also a fast-moving attack surface: typosquats, maintainer takeovers, dependency confusion, suspicious release patterns, and payloads hidden in “legit-looking” updates. Ossprey Security is built to detect these threats with a security-first view of both code behavior and package provenance. Ossprey Security is designed for security leaders and engineers who need practical guardrails in CI/CD: catch risky dependencies early, reduce triage time, and make dependency decisions with evidence, not guesswork. If you’re building or shipping with npm, PyPI, and other ecosystems, and want to harden your software supply chain, we’d love to connect.
Verified activity
Signals from Ossprey Security
3 published signals
Research & Knowledge
Ossprey Security published a writeup on the supply chain attack map, new C2 domains, and a new distribution vector.
Reported by Valentino Duval
Presence & Recognition
Ossprey Security is attending BSides Cheltenham on the 3rd of October to discuss open source and supply chain security.
Reported by Ossprey Security
Products & Services
Ossprey Security discussed worms, their damaging nature, and new NPM v12 changes.
Reported by Valentino Duval