Ossprey Security discussed worms, their damaging nature, and new NPM v12 changes.
Published
Signal category
Products & Services
Quote
“At this point we know what it is, what it is does. So instead Ossprey Security wanted to talk about what worms are, why they're so damaging, and these new NPM v12 changes that aren't necessarily going to keep organisations safe in the way they might think.”
— Valentino Duval|Ossprey Security team
Company
Ossprey Security
Securing your open source supply chain
- Industry
- Software Development
- Location
- London, GB
- Company size
- 9 employees
Ossprey Security helps teams stop malicious open-source packages before they land in production. Open source is the backbone of modern software, and it’s also a fast-moving attack surface: typosquats, maintainer takeovers, dependency confusion, suspicious release patterns, and payloads hidden in “legit-looking” updates. Ossprey Security is built to detect these threats with a security-first view of both code behavior and package provenance. Ossprey Security is designed for security leaders and engineers who need practical guardrails in CI/CD: catch risky dependencies early, reduce triage time, and make dependency decisions with evidence, not guesswork. If you’re building or shipping with npm, PyPI, and other ecosystems, and want to harden your software supply chain, we’d love to connect.
Founded 2024