Meet isomer, a new Atomdrift project. An isomer is the same formula with a different arrangement — exactly the attack shape we care about. isomer is a differential analyzer for supply-chain attack detection: instead of scoring a tree in isolation, it compares two states of the same thing — a directory, a git ref, a package, a container image — and judges whether the change is malicious. It's built to catch the subtle, xz-utils-shaped attacks where the version string says nothing happened and the behavior says otherwise.
An early build is on GitHub at atomdrift-project/isomer. Fair warning: it is experimental and in heavy development — verdicts, flags, and output formats will change without notice.
Design partners wanted
We're looking for a handful of design partners interested in the space — teams who can put isomer up against real pipelines and dependency churn, and tell us early whether we're designing the right thing. If that's you, contact details are on the isomer page.