Unmasking Malicious
Open Source Components

Explore the Backstabber's Knife Collection: A comprehensive dataset of real-world malicious packages to strengthen software supply chain security.

About the Dataset

The Backstabber's Knife Collection is a unique dataset meticulously curated to provide insights into malicious open source software components observed in real-world attacks starting 2015. Sourced from popular package repositories like npm, PyPI, and RubyGems, this collection serves as an invaluable asset for researchers, security professionals, and developers mitigating software supply chain risks.

Key Features

Engineered for robust open-source security analytics

Real-World Attacks

Contains samples from actual attacks, offering practical insights into prevalent malicious techniques.

Multi-Ecosystem Coverage

Includes malicious packages from npm, PyPI, RubyGems, and more, reflecting diverse attack vectors.

Research Backing

Based on research presented in a scientific paper, ensuring rigorous data quality and practical relevance.

Explore Malicious Package Examples

Browse malicious packages included in the dataset, dynamically filtered and categorized by ecosystem.

Access the Dataset for Full Index & Metadata

Media Coverage

Articles and academic mentions of the Backstabber's Knife Collection.

Academic Access

How to Request Access

The Backstabber's Knife Collection is freely available for verified security research and academic evaluation purposes.

Please transmit an email request to ohm[at]cs.uni-bonn.de from your institution’s official email infrastructure.

Your request must detail:
  • Your core research objectives & framework methodology
  • Your active institutional GitHub user identity
  • Note: Inquiries originating from anonymous or public providers (Gmail/Yahoo/etc.) cannot be authorized.

Citation Information

If you employ this ecosystem dataset within academic or industrial publications, kindly credit using the following schema:

BibTeX Schema
@inproceedings{ohm2020backstabber,
  title={Backstabber's Knife Collection: A Review of Open Source Software Supply Chain Attacks},
  author={Ohm, Marc and Plate, Henrik and Sykosch, Arnold and Meier, Michael},
  booktitle={DIMVA},
  year={2020},
  organization={Springer}
}