cleave & Scan v2.7.1, isomer v0.4.0
CPU work, mostly. cleave is about 25% faster; Scan and isomer embed it, so they are too. Four file-type rules that never ran now run. isomer v0.4.0 adds three detectors that need no rules.
CPU work, mostly. cleave is about 25% faster; Scan and isomer embed it, so they are too. Four file-type rules that never ran now run. isomer v0.4.0 adds three detectors that need no rules.
This cycle was about shaping isomer into something useful: verdicts being calibrated against 30 years of real supply-chain attacks, cleanups no longer read as attacks, and the LLM can never raise the CI gate. cleave and Scan v2.7.0 carry the changes isomer needed. First release where all three ship prebuilt binaries.
hood inspects the software your tools fetch — public or private — on your own machine, before you run it. It is an early experiment, released quietly to see how it behaves in the field.
isomer is our differential supply-chain attack detector: an early, experimental build that judges the change between two versions instead of scoring a tree in isolation. We're looking for a few design partners to make sure we're building the right thing.
Atomdrift Scan now ships prebuilt binaries for eight Linux architectures, macOS, the BSDs, Solaris/illumos, Android, and Windows — with a new installer at install.atomdrift.org that verifies what it downloads before it replaces anything. Testers welcome.
Files that used to produce no verdict at all — a truncated archive, a half-written gzip, a member that failed to scan — now say so. Plus ISO analysis, verified Mach-O signatures, five seconds off every cold start, and first builds for Windows, DragonFlyBSD, NetBSD, illumos/OmniOS and Solaris 11.4.
Every Atomdrift project has moved to GitHub, and we're marking the occasion with a coordinated v2.4.0: first-class dependency scanning, 16 GiB files, and faster archives — landing the same week Scan posted its best head-to-head run yet at 94% detection with zero false positives.
The headline is performance — rebuilt regex internals, parallel archive evaluation, and workers that stop hoarding memory deliver the same deterministic verdicts at a third of the memory and twice the speed — with a stack of accuracy fixes riding along.
Scan stops trusting a project's own ingredient list — v2.2.0 fetches and scans the outside code your project pulls in, screens it through bloom filters first, and inherits new formats and byte-level evidence from the engine beneath it.
The Atomdrift lab is offline for hardware maintenance today while engineers grow storage on the PostgreSQL master and its replicas to hold a 4TB dataset — the corpus of analyses we now track for more than 41 million files.
Scan learns to reach out — fetch and scan remote dependencies, packages, and URLs directly — while cleave makes YARA fast with precompiled rules and on-demand tier loading.
db-xorma's tarball carries no payload — just a clone of a real ORM whose one bolted-on method launders the attack through a real installer and a second cloned package, pulling the obfuscated BeaverTail loader from a paste host at runtime.
A package-aware wave: cleave learns DMG and go.mod, filefacts grows real lockfile parsing and PURL extraction, and stng adds generic decoded-string recovery for text.
The rest of the 2.0 stack lands alongside Atomdrift Scan: cleave's engine swap reaches stable, stng kills a class of XOR false positives, and filefacts goes panic-safe.
litmus grows up: renamed Atomdrift Scan, now generally available on pure-Rust ONNX inference, with false-positive-budget severity, an optional local-LLM second opinion, and signed model bundles.
The 707-byte package ships nothing but a fetch-and-eval; four hops later the same BeaverTail-to-InvisibleFerret kit from three prior finds is back on a brand-new IP, running a node-pty shell and hunting wallet seed phrases.
The real surf is a browser-impersonating Go library you import; the clone forgot to rename its module, turned its README into a Download button, and hides a LuaJIT screenshot-stealer in a 309 KB line of obfuscated text.
filefacts reaches 1.0.0 with richer package identity, new PE/.NET malware features, better evidence offsets, and explicit AST failure metrics for large-scale security ML pipelines.
The poison runs in your repo, not the library's — cargo's build dir leads build.rs to the consuming project's git tree, where it scrapes the latest commit's author, email and full patch, then POSTs it as a routine Sentry crash report.
Everything got a bump, and updates no longer need git: cleave and litmus now pull signed, sha256-verified .tar.zst bundles from R2 — atomic install, pin/check/update — plus richer package, PE/CLR, and Mach-O signals across the stack.
Most malicious npm packages steal; this one just deletes your source tree a minute after you install it — and its author fumbled their own online-banking password into the very same tarball.
It's the real Joyent path module, verbatim, plus three lines that fetch a jsonkeeper paste and eval it — pull that thread and it unrolls into a live DPRK BeaverTail loader and a socket.io RAT.
It ships a self-described 'cryptojacker payload' that POSTs shares to a stratum port over XHR and mines exactly nothing — yet the cookie stealer bolted onto real axios works fine, and the README reads like a startup pitch deck.
Four releases, one storyline: the filefacts engine swap deepens, and the pipeline gets dramatically cheaper to run — bounded archive analysis, a fixed ~7.7 GB regex leak, −60% peak RSS, streaming JSON everywhere.
No install hook to flag — npm auto-builds the binding.gyp it ships, which fetches its own Bun runtime to run a credential-harvesting worm outside node's view, forge Sigstore provenance, and republish the maintainer's other packages.
It promises a Roblox DataStore library and ships none of it — just an __init__.py that, on import, DPAPI-decrypts your Roblox session cookie and posts the cleartext to a Discord webhook; the README can't even spell its own name.
A 379-byte package whose only load-bearing content is a dependency version string pointing into a Google Cloud Storage bucket — so npm itself downloads and detonates the payload, and the registry never holds a copy to scan.
Two release candidates and a point release: cleave and litmus both move to 2.0.0-rc.3, closing the gap between capability extraction and the azoth model, while stng v1.5.1 stops mistaking compiler tables for hardcoded IPs.
The package you install is the real express cookie-parser, tests and all — the theft lives one require() away in a twin dependency that pulls the DPRK's BeaverTail-to-InvisibleFerret kit, run by the same crew as web-dotenv.
A tutorial-shaped AES codec whose import decrypts its own hardcoded ciphertext, pulls a 6 MB payload from nvidiadriver.net, and unpacks the Winpatch RAT — which impersonates lsass.exe to lift Chrome's app-bound encryption keys.
It stamps its own payload 'authorized testing only,' then — past the Russian comments — exfils every npmrc and env secret and drops a real Go Sliver implant beaconing to a Russian host; the PoC label is the alibi.
The Atomdrift research lab will be offline for several hours today while engineers upgrade the uplink feeding forager, the in-house crawler that has been pinned at line rate around the clock pulling releases from more than 100 software marketplaces.
A 762-byte dependency-confusion probe wearing the name of Shopify's private Shop Minis package, that slurps your CI env vars and ships them out two ways at once — HTTPS and DNS — to a Burp Collaborator.
A near-perfect copy of dotenv — 50M downloads a week — with one function bolted into config(), so booting your app fetches a stealer that combs $HOME for wallets and keys and watches your clipboard on a 750 ms loop.
The 2.0.0-rc.1 series swaps cleave's file-parsing engine out for filefacts, a standalone library you can use without the rest of cleave. litmus picks up a new JSON schema and ONNX. stng tightens the garbage filter and fixes a stack-string panic.
A 'high-performance Rust bridge' that's really a Windows dropper — IPFS payload, registry persistence, a beacon on port 2026 — whose author bundled their own config files and named the very machine they built it on.
The same Windows implant as api-rs-node, shipped 5½ hours earlier under a copy-pasted sharp README its author forgot to re-title — and the bundled config files finger the same dev machine twice over.
799 bytes, two files, and a name like a thousand throwaway npx tools — it really does check your user id, then drops a bash /dev/tcp reverse shell and calls home.
Three pre-CackalackyCon releases: stng tightens mixed binary/script decoding, litmus improves worker reporting and model bundle handling, and cleave deepens PDF and LNK analysis.
Preview support for the azoth ensemble. Multi-seed averaging, per-route isotonic calibration, LightGBM alongside XGBoost. Models route per file from a top-level config.
cleave diff is the signal we have been building toward: a structured, scoped delta between two versions of the same software, with an estimated rate of change that nobody else is measuring. kv now covers PE/ELF/Mach-O along with Office, PDF, PyInstaller, CHM, and a long tail of source and archive formats, with much deeper binary provenance.
The lab's PostgreSQL master is offline: btrfs filled up and now refuses to delete files — or even snapshots — because it is out of space. No data was lost, thanks to our distributed replica architecture. We are moving the master to ZFS on OmniOS and teaching the lab to fail over to a replica. ETA back online: today.
Go and Rust PE recovery, multi-key XOR via lea-near-xor analysis, and a pile of fixes for things that were quietly wrong.
cleave fixes a class of rayon deadlocks, parses Python pickle and MSI-embedded PE, and skips rizin on Go binaries for a real speedup; litmus gains worker-mode fleet scanning behind a hardened HTTP server; stng stops mis-flagging Kotlin as Python.
Preserve Telegram bot tokens, JWTs, and Swift mangled symbols that the chaos filter was dropping; cut XOR IP false positives inside binary data tables.
PE Authenticode chain extraction and ~100 new ELF/Mach-O fields; archive scanning raised from 1K to 100K members; breaking V4 output schema.
Aho-Corasick rewrite of XOR/string classification and parallel disassembly via iced-x86; fixes a PE/XOR bug that was missing office_update-style samples.
Atomdrift launches: an open-source pipeline for catching supply-chain attacks the static-binary tools miss. First piece is litmus.
First tagged release. Open-source malware classifier with TreeSHAP-explained verdicts; CPU-only, offline, no telemetry. Default model is beta — not production-ready yet.