Supply-chain malware detection for your code, not just a vendor's index.
Every hosted scanner answers one question: is this package on our list yet? Atomdrift reads the artifact — source, binaries, containers, archives, private packages — and scores what it can actually do. Nothing to be listed on, nothing to wait for, and it works on the code no vendor indexes.
2026-08-12 · 45 live samples, median 11 h old.
Caught, per engine identical cohort · a skip counts as a miss
Every engine is scored at its most sensitive setting, ours included. Grey is scope — an engine that only reads registry packages marks the rest of the cohort unsupported, which the methodology scores as a miss.
Detection vs. false positives every rival ships one setting — -l is a dial you set
Detection and false-positive chart data
- VirusTotal: 64% caught (29 of 45), 0 false positives of 50.
- Aikido Malware: 29% caught (13 of 45), 0 false positives of 50.
- ClamAV: 22% caught (10 of 45), 0 false positives of 50.
- GuardDog: 29% caught (13 of 45), 1 false positive of 50.
- Socket: 20% caught (9 of 45), 0 false positives of 50.
- SafeDep: 2% caught (1 of 45), 0 false positives of 50.
- malcontent: 38% caught, 20 false positives of 50.
- Atomdrift at -l 0 through 6: 33% caught (15 of 45), 0 false positives of 50.
- Atomdrift at -l 7 through 312: 58% caught (26 of 45), 2 false positives of 50.
- Atomdrift at -l 313 through 749: 60% caught (27 of 45), 2 false positives of 50.
- Atomdrift at -l 750 through 2500: 93% caught (42 of 45), 2 false positives of 50.
-l is a false-positive budget — files flagged per 100 million, calibrated per
file type. Not “medium sensitivity”; a number you can plan a pipeline around. The curve runs
-l 0 to -l 2,500 through
4 measured operating points, spans between them interpolated.
False-positive axis inverted and cropped at 10%; malcontent is past it, drawn below the break at 40%. Hover any mark for exact counts.
Every previous run a fresh cohort each time
Most engines swing sixty points as the samples change. Judge us on the worst night, not the best.
Three structural differences architecture, not features
The first two are measurable, and this run measures them. 26 of 45 samples weren't registry packages at all — binaries, executables, archives. That is also the shape of your own code.
| Engine | Couldn't read | Could look up | No record yet | Caught |
|---|---|---|---|---|
| Socket | 31 | 14 | 5 | 9 |
| GuardDog | 31 | 14 | — | 13 |
| SafeDep | 30 | 15 | 14 | 1 |
| Aikido Malware | 26 | 19 | 6 | 13 |
“No record yet” is the detection gap, measured: a live malicious package the vendor indexes and had no entry for at the moment we asked. VirusTotal, Atomdrift, malcontent, ClamAV read every sample. How it decides →
Appendix — samples and methodology all 45, every one linked
How this is scored. Every engine gets the identical cohort, and a skip counts as a miss for all of them — a file nobody scanned is a file that got through. A listing from a contestant's own feed counts only once an independent engine corroborates it. Known-good packages come from the freshest 48 hours of the open-source firehose and are re-checked later: one that turns out to be malware leaves that run's false-positive rates, and any engine that flagged it is credited with an early detection. We run this benchmark and we're one of the engines in it, so every sample, verdict and rate is published.
Engine versions: Atomdrift 2.6.0 · ClamAV 1.5.3 · GuardDog 3.2.0 (locally-run engines; VirusTotal, Socket, Aikido Malware, SafeDep are hosted services queried live, so they carry no pinned version).
Point it at your own code.
Apache-2.0 · runs locally · no account, no index