Provides a comprehensive taxonomy of supply chain risk signals, emphasizing behavioral analysis and hidden malicious delivery vectors.
Socket provides a detailed taxonomy of over 50 supply chain risk alerts across major ecosystems like JavaScript, Python, Go, and Java. Critical alerts focus on known malware and typosquatting attacks, while high-severity alerts identify obfuscated code, telemetry, protestware, and the use of Git or HTTP dependencies. Medium-severity alerts track behavioral signals such as native code execution, network access, shell access, and the use of `eval()`. Quality and maintenance alerts monitor unmaintained or deprecated packages, and license alerts detect unlicensed items, copyleft violations, and non-permissive license classifiers.
Socket alerts on install script execution, native code, shell access, and network access during package installation — all behavioral signals that overlap with install-time attack vectors.
arbitrary code execution during installation enabling credential theft, data exfiltration, or persistent backdoors
Socket's behavioral analysis taxonomy validates that install-time execution is a primary delivery vector for supply chain malware across all major ecosystems.
Critical alerts for Known Malware and AI-detected potential malware are central to Socket's detection engine.
execution of known malicious payloads during development or production
identifying active malware is the highest-priority defense for any software supply chain security tool.
Alert types: Obfuscated code, Telemetry, Network access, Shell access, Uses eval, Native code.
Risk Guard focuses on metadata and vulnerabilities but does not perform static analysis to detect the 'Capabilities' (e.g., shell access, network access) of a package.
Risk Guard would be better if it flagged the 'Permissions' or 'Capabilities' of a package (e.g., Network/FS/Shell access) to alert on unexpected behaviors.