Ian Kretz
@ikretz.bsky.social
72 followers 26 following 5 posts
Security Research @ Datadog
Posts Media Videos Starter Packs
ikretz.bsky.social
My colleague, Sebastian Obregoso, and I had the privilege of writing a guest post for OpenSSF's blog on how we detect malicious open source packages at @securitylabs.datadoghq.com using GuardDog.

Check it out here: openssf.org/blog/2025/03...
GuardDog: Strengthening Open Source Security Against Supply Chain Attacks – Open Source Security Foundation
openssf.org
ikretz.bsky.social
Meanwhile, GuardDog findings are more like indicators of potentially suspicious or malicious package behavior rather than a conclusive determination. Review of the findings is crucial to how we produce a high-quality dataset for SCFW to consume.
ikretz.bsky.social
Hi, I work on both projects. SCFW consults our dataset of human-reviewed malicious packages to determine when to block. Unlike GuardDog, it doesn't do any package scanning of its own.
Reposted by Ian Kretz
securitylabs.datadoghq.com
Interested in malicious software packages? Our open-source dataset just hit over 5,000 samples of malicious npm and PyPI packages!

github.com/DataDog/mali...