Atomdrift Scan · supply-chain malware detection · Apache-2.0

Open-source malware scanning on your infrastructure.

Scan source, binaries, packages, archives, URLs, and running processes with local static analysis and ONNX models. No cloud scanner or API key is required, and every verdict includes the capabilities that drove it.

Built for security teams that need an inspectable CLI, an air-gap mode, CI-friendly exit codes, or an engine they can embed and self-host.

curl -fsSL https://install.atomdrift.org/scan.sh | sh
Apache-2.0 47 registries 100+ file types no telemetry Linux · macOS · BSD · illumos
82%
malware caught
2%
false alarms
-l 0-l 25000
at -l 50 — the shipped default, untuned

As of 2026-08-06.

Latest results 50 malware samples, none older than 48 hours · 2026-08-06

Atomdrift
82%
VirusTotal
64%
malcontent
46%
Socket
32%
ClamAV
22%
SafeDep
22%
GuardDog
20%
Aikido Malware
16%
flagged hostile flagged suspicious unsupported file format

Every engine is scored at its most sensitive setting, ours included. 90% is the top of our dial; 82% is the shipped default. Both beat the field.

Grey is scope: engines that only read packages from registries they support mark the rest of the cohort as an unsupported file format.

Catch rate vs. false alarms everyone else is a dot — we're the line

Only the top-right corner counts: catch the malware, spare the clean code. Every rival is one dot — one setting, chosen for you. We're the curve.

0% 25% 50% 75% 100% 0% 10% 20% 30% 40% 50% Conservative The corner that matters Trailing Aggressive Malware caught · higher is better → False alarms · fewer is better ↑ VirusTotal [62 engines] — 64% caught · 0% false VirusTotal [62 engines] 64% caught · 0% false Socket — 32% caught · 0% false Socket 32% caught · 0% false malcontent — 46% caught · 37% false malcontent 46% caught · 37% false ClamAV, SafeDep — 22% caught · 0% false 2 ClamAV SafeDep 22% caught · 0% false GuardDog — 20% caught · 0% false GuardDog 20% caught · 0% false Aikido Malware — 16% caught · 0% false Aikido Malware 16% caught · 0% false atomscan -l 0–5 — 54% caught · 2% false alarms Atomdrift · L:0 54% caught atomscan -l 25–500 — 82% caught · 2% false alarms L:50 (DEFAULT) 82% caught atomscan -l 1000–25000 — 90% caught · 4% false alarms L:25,000 90% caught

Catch rate and false-alarm chart data

  • VirusTotal [62 engines]: 64% caught · 0% false.
  • Socket: 32% caught · 0% false.
  • malcontent: 46% caught · 37% false.
  • ClamAV: 22% caught · 0% false.
  • SafeDep: 22% caught · 0% false.
  • GuardDog: 20% caught · 0% false.
  • Aikido Malware: 16% caught · 0% false.
  • Atomdrift L 0 through 5: 54% caught, 2% false alarms.
  • Atomdrift L 25 through 500: 82% caught, 2% false alarms.
  • Atomdrift L 1000 through 25000: 90% caught, 4% false alarms.

-l is a false-positive budget — files flagged per 100 million, calibrated per file type. Not “medium sensitivity”; a number you can plan a pipeline around.

50 malware samples against 49 known-good packages. False-alarm axis inverted, so up and right is better.

Every run before this one each draws a fresh cohort from live feeds

Most engines swing sixty points as the cohort changes. Judge us on the worst night, not the best.

Each run draws a fresh cohort, so movement is the samples changing as much as the engines.

How it differs static analysis in addition to reputation

Reputation is useful for known files, but a newly published package may have no record. Atomdrift checks known-good and known-bad hashes first, then unpacks the artifact, extracts capabilities from its code and structure, and scores that evidence locally. How it works →

It's yours Apache-2.0 — embed it, fork it, ship it in something you sell

Socket, Aikido, SafeDep and VirusTotal are services you rent. That's not a licensing detail — it decides what you're allowed to build.

A scanner you rent
  • Priced per seat or per scan, forever
  • Needs the network — no air-gap, no offline CI
  • Can't go inside a product you sell
  • Can't see the rule that flagged your build
  • A false positive gets fixed when the vendor feels like it
  • Your code goes to their servers
A scanner you own
  • Apache-2.0. Free at any volume, forever
  • Runs air-gapped after bundles are installed
  • Embed it in your own product and sell that
  • Engine, traits, and model bundles are inspectable
  • Fix it yourself this afternoon, or fork it
  • Files are analyzed locally; update and reference fetching are controllable

Run atomscan version to inspect the exact traits, YARA rules, bloom filters, and ONNX models installed on a machine. The same engine is available as a CLI, library, HTTP service, or distributed worker, so teams can move from a workstation to a scan fleet without changing the analysis model.

Appendix — samples and methodology all 50, every one linked
pkg:npm/@cacheable/utils@2.5.0 pkg:npm/@ikbal_fadilah_vanexa01/vanexa-agent@1.3.10 pkg:npm/@qlik/sprout-react@6.45.3 pkg:npm/app-kst-engine@2.1.6 pkg:npm/1ace1637c592ae3779104f804ba54b1de737fee1dfca4948dd908b6243363a99 pkg:npm/99dc940e1b3ba041885dd9a89e2d24bf067713238e831ae3d415282ec98e07c0 pkg:npm/664e8ea263f2cec14927d140deb99bfa8e9cf3194bc64afdb2bbc492e5d34057 boatnet.arm6 boatnet.i486 pkg:npm/claude-remote-agent@0.1.0 pkg:npm/clawtrl-wallet@1.5.1 pkg:npm/243702bc07e2c666ad7fef0457748b7b1bcad27dc9733fd24f44456382e50a67 pkg:npm/dolyame-ui-storybook-menu@35.5.6 pkg:npm/ezdiscordbots@1.0.2 file pkg:pypi/gcli-control@0.11.1 pkg:pypi/gcli-control@0.12.2 pkg:golang/github.com/archlinuxcn/repo@v0.0.0-20260805050719-24c35dab56c8 pkg:maven/io.github.davidtimur:c2-lab@1.0.1 pkg:npm/kepler@1.999.999 killbotx.mips killbotx.mipsel KO Common App Essay V3.docx pkg:pypi/meshcode@2.11.212 mips pkg:pypi/numpyp@0.7.7 pkg:npm/5fd276cac6c062df5554e2a6f2c776f64743db9f431bc3323b6c1df8bc978dad pdf_Receipt_20260803_1437.js pkg:npm/picasso-plugin-hammer@2.11.5 Prestige-Client.exe pkg:npm/18fddcf08bcfa108776f316b823669a82836e4c20526b3fc0a0e5433b63ef689@37851 putita.arm5 putita.mips pkg:npm/28359d2d8054f8650bfdb99aa395ef2bba62846005e3f4748b2aca8f173f8bcb@1149 pkg:npm/tinkoff-boxy-mobile-vivid-heading@20.7.5 pkg:pypi/uncrypt@0.1.0 virussign.com_006c337c550ab4a1404098c1983f5040.vir virussign.com_10a8ebcb832e0221f9082c056e5436b0.vir virussign.com_13c6e46b1b886da8326d1c2c641ad700.vir virussign.com_1b9dfc8b7c488b60ebba58987aa6fc10.vir virussign.com_380f8057325045104380f05540a46260.vir virussign.com_3922f1b36bfb1d052ec880685830f390.vir virussign.com_85c654f48e4999e041d6681988c309f0.vir virussign.com_90f6c6e524be646c8ad437a5f3ad9170.vir virussign.com_9cb21979de549773fe1662f354ec40e0.vir virussign.com_b1f92833fd05b9e0348ef069d1b7be10.vir virussign.com_db8f1af8c52f8d09f477abaa7cac23c0.vir pkg:npm/web3-utils-crypto@1.10.4 wyhrytj.exe x86
How this is scored. Samples come from live public malware feeds, none older than 48 hours. Every engine gets the identical cohort, and a skip counts as a miss for all of them — a file nobody scanned is a file that got through. A listing from a feed belonging to one of the contestants only counts once an independent engine corroborates it, so nobody is credited for their own report. Presumed-good packages are drawn from the freshest 48 hours of the open-source firehose and re-checked on later runs: one that turns out to be malware is removed from that run's false-positive rates, and any engine that flagged it is credited with an early detection. We run this benchmark and we're one of the engines in it, so every sample, verdict and rate is published.

Engine versions: Atomdrift 2.5.0 · ClamAV 1.5.3 · GuardDog 3.1.0 (locally-run engines; VirusTotal, Socket, Aikido Malware, SafeDep are hosted services queried live, so they carry no pinned version).

Point it at your dependencies.

Apache-2.0 · local analysis · explicit offline mode

curl -fsSL https://install.atomdrift.org/scan.sh | sh