Atomdrift Scan · supply-chain malware detection · Apache-2.0

Open-source malware scanning on your infrastructure.

Scan source, binaries, packages, archives, URLs, and running processes with local static analysis and ONNX models. No cloud scanner or API key is required, and every verdict includes the capabilities that drove it.

Built for security teams that need an inspectable CLI, an air-gap mode, CI-friendly exit codes, or an engine they can embed and self-host.

curl -fsSL https://install.atomdrift.org/scan.sh | sh
Apache-2.0 47 registries 100+ file types no telemetry Linux · macOS · BSD · illumos
71%
malware caught
0%
false alarms
-l 0-l 25000
at -l 50 — the shipped default, untuned

As of 2026-08-10.

Latest results 48 malware samples, none older than 48 hours · 2026-08-10

Atomdrift
71%
VirusTotal
63%
malcontent
42%
Aikido Malware
31%
Socket
29%
ClamAV
25%
GuardDog
13%
SafeDep
6%
flagged hostile flagged suspicious unsupported file format

Every engine is scored at its most sensitive setting, ours included. 88% is the top of our dial; 71% is the shipped default. Both beat the field.

Grey is scope: engines that only read packages from registries they support mark the rest of the cohort as an unsupported file format.

Catch rate vs. false alarms everyone else is a dot — we're the line

Only the top-right corner counts: catch the malware, spare the clean code. Every rival is one dot — one setting, chosen for you. We're the curve.

0% 25% 50% 75% 100% 0% 10% 20% 30% 40% Conservative The corner that matters Trailing Aggressive Malware caught · higher is better → False alarms · fewer is better ↑ VirusTotal [65 engines] — 63% caught · 2% false VirusTotal [65 engines] 63% caught · 2% false Aikido Malware — 31% caught · 0% false Aikido Malware 31% caught · 0% false Socket — 29% caught · 2% false Socket 29% caught · 2% false ClamAV — 25% caught · 2% false ClamAV 25% caught · 2% false malcontent — 42% caught · 32% false malcontent 42% caught · 32% false GuardDog — 13% caught · 6% false GuardDog 13% caught · 6% false SafeDep — 6% caught · 0% false SafeDep 6% caught · 0% false atomscan -l 0 — 23% caught · 0% false alarms Atomdrift · L:0 23% caught · no false alarms atomscan -l 1–5 — 25% caught · 0% false alarms atomscan -l 25–500 — 71% caught · 0% false alarms L:50 (DEFAULT) 71% caught · no false alarms atomscan -l 1000–25000 — 88% caught · 8% false alarms L:25,000 88% caught

Catch rate and false-alarm chart data

  • VirusTotal [65 engines]: 63% caught · 2% false.
  • Aikido Malware: 31% caught · 0% false.
  • Socket: 29% caught · 2% false.
  • ClamAV: 25% caught · 2% false.
  • malcontent: 42% caught · 32% false.
  • GuardDog: 13% caught · 6% false.
  • SafeDep: 6% caught · 0% false.
  • Atomdrift L 0: 23% caught, 0% false alarms.
  • Atomdrift L 1 through 5: 25% caught, 0% false alarms.
  • Atomdrift L 25 through 500: 71% caught, 0% false alarms.
  • Atomdrift L 1000 through 25000: 88% caught, 8% false alarms.

-l is a false-positive budget — files flagged per 100 million, calibrated per file type. Not “medium sensitivity”; a number you can plan a pipeline around.

48 malware samples against 50 known-good packages. False-alarm axis inverted, so up and right is better.

Every run before this one each draws a fresh cohort from live feeds

Most engines swing sixty points as the cohort changes. Judge us on the worst night, not the best.

Each run draws a fresh cohort, so movement is the samples changing as much as the engines.

How it differs static analysis in addition to reputation

Reputation is useful for known files, but a newly published package may have no record. Atomdrift checks known-good and known-bad hashes first, then unpacks the artifact, extracts capabilities from its code and structure, and scores that evidence locally. How it works →

It's yours Apache-2.0 — embed it, fork it, ship it in something you sell

Socket, Aikido, SafeDep and VirusTotal are services you rent. That's not a licensing detail — it decides what you're allowed to build.

A scanner you rent
  • Priced per seat or per scan, forever
  • Needs the network — no air-gap, no offline CI
  • Can't go inside a product you sell
  • Can't see the rule that flagged your build
  • A false positive gets fixed when the vendor feels like it
  • Your code goes to their servers
A scanner you own
  • Apache-2.0. Free at any volume, forever
  • Runs air-gapped after bundles are installed
  • Embed it in your own product and sell that
  • Engine, traits, and model bundles are inspectable
  • Fix it yourself this afternoon, or fork it
  • Files are analyzed locally; update and reference fetching are controllable

Run atomscan version to inspect the exact traits, YARA rules, bloom filters, and ONNX models installed on a machine. The same engine is available as a CLI, library, HTTP service, or distributed worker, so teams can move from a workstation to a scan fleet without changing the analysis model.

Appendix — samples and methodology all 48, every one linked
31159be01493eeb09cf3b299702a6369.exe 6cae7a11941d4b5993a30bccf786ee39d0051736443df539b7c8cf551d8d4986.elf 9e3363f017c60726bf610a2a472040144T.rar 9ea2f55c1c91d04820f5082cf113c73c6320b157baa98d69654117cfc8458296 pkg:npm/@bobfrankston/[email protected] pkg:npm/@lambda-platform/[email protected] pkg:npm/@ornikar/[email protected] pkg:npm/@ssgw/[email protected] pkg:npm/@vertexa/[email protected] bot.386 pkg:pypi/[email protected] pkg:pypi/[email protected] pkg:npm/[email protected] pkg:pypi/[email protected] pkg:pypi/[email protected] pkg:pypi/[email protected] pkg:pypi/[email protected] pkg:pypi/[email protected] pkg:pypi/[email protected] pkg:pypi/[email protected] David.ppc pkg:npm/[email protected] k.php pkg:npm/[email protected] ok Payment Slip9570-6758636.xls pid.powerpc pkg:npm/[email protected] support.client.exe T. HALK BANKASI.com tokar821-polymarket-kalshi-arbitrage-bot.tar.gz upload upload upload upload upload virussign.com_139186fbe4e28ea9bfea906f1347ad90.vir virussign.com_26b23f27e8410e190c24d2c9466871f0.vir virussign.com_5b30b33fe373103f401f63a7c7e01b80.vir virussign.com_6cc4a7041991581b747a32e099939290.vir virussign.com_8630fa01db6ef6d2fcaf00a32656a830.vir virussign.com_99a2bf105df43d45e6ef9383ed788b70.vir virussign.com_a150f3e972fb9e81e8f3c5b8f8e367f0.vir virussign.com_a17ab77f9a93c96a7d6d53b1f360af40.vir virussign.com_bc8b21f5afdd143d8465e6649008b3a0.vir virussign.com_c682e3cf0de7c4e0f1615f9b089c34f0.vir virussign.com_e65b9b93c9cff432693e3afa60022060.vir x86_64
How this is scored. Samples come from live public malware feeds, none older than 48 hours. Every engine gets the identical cohort, and a skip counts as a miss for all of them — a file nobody scanned is a file that got through. A listing from a feed belonging to one of the contestants only counts once an independent engine corroborates it, so nobody is credited for their own report. Presumed-good packages are drawn from the freshest 48 hours of the open-source firehose and re-checked on later runs: one that turns out to be malware is removed from that run's false-positive rates, and any engine that flagged it is credited with an early detection. We run this benchmark and we're one of the engines in it, so every sample, verdict and rate is published.

Engine versions: Atomdrift 2.6.0 · ClamAV 1.5.3 · GuardDog 3.1.0 (locally-run engines; VirusTotal, Socket, Aikido Malware, SafeDep are hosted services queried live, so they carry no pinned version).

Point it at your dependencies.

Apache-2.0 · local analysis · explicit offline mode

curl -fsSL https://install.atomdrift.org/scan.sh | sh