Saturday, February 7, 2026
No Result
View All Result
  • Home
  • Guest Post
  • Submit Review Article
  • Contact
Somali Update
  • Headlines
    • Politics
  • Auto
    • Bike
    • Car
  • Business
    • Finance
    • Funding
    • Internet Marketing
    • Entrepreneurship
    • Startups
    • Insurance
    • Real Estate
  • Crypto
    • Bitcoin
    • Ethereum
    • Altcoins
    • Crypto Airdrop
    • ICO News
  • Entertainment
    • Poll
    • Quiz
  • Lifestyle
    • Health
    • Fashion
    • Food
    • Romance
    • Travel
  • Sports
    • Baseball
    • Basketball
    • Cricket
    • Football
    • Hockey
    • NFL
    • Tennis
    • WWE
  • Tech
    • Gadgets
    • Hardware
    • Software
    • Android
    • iOS
    • Social Media
  • Casino
    • Betting
  • Headlines
    • Politics
  • Auto
    • Bike
    • Car
  • Business
    • Finance
    • Funding
    • Internet Marketing
    • Entrepreneurship
    • Startups
    • Insurance
    • Real Estate
  • Crypto
    • Bitcoin
    • Ethereum
    • Altcoins
    • Crypto Airdrop
    • ICO News
  • Entertainment
    • Poll
    • Quiz
  • Lifestyle
    • Health
    • Fashion
    • Food
    • Romance
    • Travel
  • Sports
    • Baseball
    • Basketball
    • Cricket
    • Football
    • Hockey
    • NFL
    • Tennis
    • WWE
  • Tech
    • Gadgets
    • Hardware
    • Software
    • Android
    • iOS
    • Social Media
  • Casino
    • Betting
No Result
View All Result
Somali Update
No Result
View All Result

Apiiro Unveils Free Tools to Fight Malicious Code in Software Supply Chains

by Susan James
12 months ago
in News, Technology
Reading Time: 4 mins read
0
Home News
Share on FacebookShare on TwitterShare on WhatsAppShare on Telegram

Security researchers at Apiiro have just raised the stakes in the battle against supply chain attacks. They’ve launched two new open-source tools aimed at detecting and blocking malicious code before it makes its way into software projects—a proactive move in a world where code-based threats are becoming increasingly stealthy and sophisticated.

With supply chain attacks on the rise, these free tools could be a game-changer for developers and cybersecurity teams alike. Here’s how they work, why they matter, and what they could mean for the future of secure software development.

A Two-Pronged Defense Against Malicious Code

At the core of Apiiro’s new release are two tools: a comprehensive ruleset for Semgrep and Opengrep, and a GitHub-integrated scanner called PRevent. Both are designed to catch malicious code before it gets merged into production.

Let’s break that down:

  • Semgrep and Opengrep Rulesets: These are pattern detection tools that help identify code behaviors often associated with malware.
  • PRevent: A real-time GitHub scanner that watches for suspicious activity in pull requests (PRs) before any code gets merged.

Matan Giladi, a security researcher at Apiiro, claims these tools keep false positives low while maintaining high accuracy rates—making them practical for real-world applications where efficiency matters.

Apiiro malicious code detection tools GitHub

How Accurate Are These Tools?

When it comes to stopping threats, accuracy is everything. According to Apiiro’s internal tests:

  • The detection accuracy for PyPI packages is 94.3%—a strong performance for Python environments.
  • For npm packages, which are typically used for JavaScript projects, the accuracy is slightly lower but still impressive at 88.4%.
  • PRevent flags malicious pull requests correctly 91.5% of the time.

These are solid numbers for an open-source project, especially considering the typical trade-off between catching threats and avoiding false alarms.

Spotting the Bad Apples: How the Detection Works

Apiiro’s detection strategy revolves around identifying what they call “code anti-patterns”—these are behaviors that rarely show up in legitimate code but often appear in malware. The focus is on static analysis, meaning the code is scanned without executing it, keeping the system secure from accidental infections.

Here’s what the system looks for:

  • Obfuscation Techniques: Encoding, nested transformations, and runtime changes that mask the true purpose of the code.
  • Suspicious Functions: Calls to exec() or eval(), which can execute arbitrary code—a hallmark of many malicious scripts.
  • External Payloads: Code that tries to download and run files from unknown servers.
  • Data Exfiltration: Attempts to send sensitive user information to external locations.

These red flags aren’t always definitive proof of malicious intent, but they are strong indicators that something’s off.

Integrating the Tools Into Your Workflow

One of the standout features of Apiiro’s solution is how seamlessly it integrates into existing workflows. Developers can plug the ruleset directly into their CI/CD pipelines for automated scanning. This means every push or pull request can be checked automatically, without slowing down the development process.

Key benefits:

  • Automated scans for npm and PyPI packages.
  • Customizable rules for different platforms using Semgrep or Opengrep.
  • Real-time alerts for pull requests flagged by PRevent.

And for extra security, PRevent can be configured to:

  • Block suspicious pull requests until a reviewer signs off.
  • Add comments on flagged code so developers are immediately aware of potential issues.

The Limitations (And What’s Coming Next)

No tool is perfect, and Apiiro’s offerings have their limitations:

  • They can’t detect malware hidden in compiled binaries.
  • Direct scanning of npm and PyPI packages isn’t yet supported.

However, Apiiro has already hinted at future updates, including:

  • Deep code analysis for catching more sophisticated threats.
  • AI-assisted scans to improve detection rates and reduce false positives.

If these features roll out as planned, Apiiro’s tools could become a major player in the fight against software supply chain attacks.

Where to Get These Tools

Both the malicious code detection ruleset and PRevent are available for free on GitHub. Detailed instructions for installation and usage are provided, making it easy for developers and security professionals to get started.

One caveat: As of now, these tools haven’t been independently tested by platforms like BleepingComputer. So, while the promise is high, users should proceed with a mix of optimism and caution.

Susan James

Susan James

Susan James is a talented author and a skilled content writer. As a content writer, Susan has honed her skills in researching and understanding various topics, allowing her to produce well-rounded and engaging pieces across a wide range of subjects.

Related Posts

With Love Tamil movie

With Love Tamil Movie Reviews Win Hearts on X

14 hours ago
Windows 11 January update is causing Nvidia gaming issues

Windows 11 January Update Triggers Nvidia Gaming Issues

14 hours ago
Luka Doncic

Luka Doncic Injury Scare Clouds Lakers Loss to 76ers

14 hours ago
Tesla CEO Elon Musk says 2026 could be the year robotaxi

Tesla Expects Big Robotaxi Growth in 2026 and Beyond

14 hours ago
KDE Plasma 6.7.0

KDE Plasma 6.7.0 Adds One Key Fix Users Asked For

7 days ago
Corus seeks court approval for a recapitalization deal after a shareholder vote fails

Corus Seeks Court Approval After Recap Deal Fails Vote

7 days ago

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

SEARCH

No Result
View All Result

TRENDING

  • Trending
  • Comments
  • Latest
Raja Rani Coupon Result

Raja Rani Result Today: Raja Rani Result 28th August Live Updates

August 28, 2024
SkymoviesHD

SkymoviesHD Proxy to Unblock Site – SkymoviesHD Movies Download

March 6, 2024
Control Bionics Secures Major US Reimbursement for NeuroNode Device

Control Bionics Secures Major US Reimbursement for NeuroNode Device

August 19, 2024
Moviesda

Moviesda Proxy to Unblock Links – Moviesda Movie Download

March 6, 2024
near lossless electrical transmission discovery by mit scientists

Near-Lossless Electrical Transmission: A Breakthrough by MIT Scientists

September 12, 2024
Bigg Boss 7 Tamil Contestants Salary

Bigg Boss 7 Tamil Contestants Salary Per Day Revealed

January 9, 2024
Kolkata FF Fatafat Result

Kolkata FF Fatafat Result 24th January 2024 Live Updates

January 24, 2024
Vegamovies

Vegamovies Proxy to Unblock Links – Vegamovies Movies Download

March 6, 2024
iBOMMA

iBOMMA Proxy to Unblock, Movies – IBOMMA Movie Download

March 6, 2024
Tamilblasters

TamilBlasters Proxy – Unblock Links, Tamilblasters Movies Download

March 6, 2024

Business Ideas with Low Investment and High Profit

1
Bhutan Teer Result 2021

Bhutan Teer Result Today Live: Bhutan Teer Result 3rd January Update

1

Reasons to Join the PKT Cash Crypto Network

1
Kolkata FF Fatafat Result

Kolkata FF Fatafat Result 24th January 2024 Live Updates

1
Coinbase

Coinbase Crypto Exchange hires Jeff Horowitz as their CCO

0
Kucoin

KuCoin Scam? Office Location issue clarified

0
Nokia 5G mobile

Nokia 5G Mobile to be launched with T-Mobile soon

0
CasinoBuzz

Casino.Buzz: One of the most Informative Online Casino Review Website

0
Facebook Ban alex jones

Facebook Suspends Alex Jones for Hate Speech

0
Good Rummy Party

What Makes a Good Rummy Party?

0
With Love Tamil movie

With Love Tamil Movie Reviews Win Hearts on X

February 6, 2026
Windows 11 January update is causing Nvidia gaming issues

Windows 11 January Update Triggers Nvidia Gaming Issues

February 6, 2026
Luka Doncic

Luka Doncic Injury Scare Clouds Lakers Loss to 76ers

February 6, 2026
Tesla CEO Elon Musk says 2026 could be the year robotaxi

Tesla Expects Big Robotaxi Growth in 2026 and Beyond

February 6, 2026
money in motorcycle industry

5 Proven Ways to Cash In on the Motorcycle Industry

February 3, 2026
KDE Plasma 6.7.0

KDE Plasma 6.7.0 Adds One Key Fix Users Asked For

January 31, 2026
Corus seeks court approval for a recapitalization deal after a shareholder vote fails

Corus Seeks Court Approval After Recap Deal Fails Vote

January 31, 2026
AI is moving closer

AI Surgery Stocks Could Shape the Future of Medicine

January 31, 2026
Cooper Flagg

Cooper Flagg Drops 49 in Epic Rookie Duel vs Hornets

January 30, 2026
CoreWeave stock rebounds as Nvidia

CoreWeave Stock Rebounds as Nvidia Tie Fuels Fresh AI Optimism

January 30, 2026

ABOUT US

From global politics to cultural trends, we bring you comprehensive coverage and diverse perspectives. Stay connected with the international community and explore stories from around the globe. Engage with our thought-provoking articles and stay informed about the world’s most pressing issues.

Contact us at ceo.somaliupdate@gmail.com

ADVERTISE WITH US

We accept following advertisement methods in our website.

  • Guest Post
  • Sponsored Post
  • Banner Ad
  • Homepage Ad
  • Sidebar Ad
  • Niche Edit
  • Link Ad
  • Review Article

POPULAR CATEGORIES

List of Popular categories in our websites which are loved more frequently by our beloved readers.

  • AUTO
  • BUSINESS
  • CRYPTO
  • GAMBLING
  • SPORTS
  • TECH
  • HEALTH

THIS WEEK POLLS

Sorry, there are no polls available at the moment.
  • Polls Archive
  • Home
  • Guest Post
  • Submit Review Article
  • Contact

© 2023 SOMALIUPDATE - Developed by VISION

No Result
View All Result
  • Headlines
    • Politics
  • Auto
    • Bike
    • Car
  • Business
    • Finance
    • Funding
    • Internet Marketing
    • Entrepreneurship
    • Startups
    • Insurance
    • Real Estate
  • Crypto
    • Bitcoin
    • Ethereum
    • Altcoins
    • Crypto Airdrop
    • ICO News
  • Entertainment
    • Poll
    • Quiz
  • Lifestyle
    • Health
    • Fashion
    • Food
    • Romance
    • Travel
  • Sports
    • Baseball
    • Basketball
    • Cricket
    • Football
    • Hockey
    • NFL
    • Tennis
    • WWE
  • Tech
    • Gadgets
    • Hardware
    • Software
    • Android
    • iOS
    • Social Media
  • Casino
    • Betting

© 2023 SOMALIUPDATE - Developed by VISION