Built something? We create video reels & spotlights for GitHub projects.Promote your project →
ossf
Home / Go / malicious-packages

ossf/malicious-packages

A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.

Go ◇ developer-tools Apache-2.0
★622STARS
⑂157FORKS
!60ISSUES
🏆#6,311GLOBAL RANK
🔥2DAYS TRENDING
🚀
Maintainer Growth Kit for malicious-packages

Claim this project, add your verified backlink badge to your README, and download milestone cards.

Claim Repo

Star History

Continuous Observations
Interactive star growth chart for ossf/malicious-packages
CSV
⭐ VIRAL README KIT

Add Live Star History & Verified Badges to README.md

Keep your repository README looking professional and dynamic. As our continuous crawler records new stars, these official SVG badges update in real time with zero maintenance.

Open README on GitHub ↗
Option 1: Interactive Star History Chart Dynamic SVG

Renders your high-resolution star trajectory chart right inside your GitHub README or project docs.

ossf/malicious-packages Star History Preview
markdown
[![Star History Chart](https://githubrepo.cloud/api/badge/chart/ossf/malicious-packages.svg?theme=dark)](https://githubrepo.cloud/repo/ossf/malicious-packages?utm_source=readme_chart)
Direct SVG Link ↗
Option 2: Verified Shields Badges Shields.io Style

Compact Shields-style badges for your README header. Shows real-time stars and global ranking.

Featured badge Stars badge Rank badge
markdown (badge trio)
[![Featured on GitHubRepo.cloud](https://githubrepo.cloud/badge/ossf/malicious-packages.svg?metric=featured)](https://githubrepo.cloud/repo/ossf/malicious-packages?utm_source=readme_badge) [![GitHubRepo Stars](https://githubrepo.cloud/badge/ossf/malicious-packages.svg?metric=stars)](https://githubrepo.cloud/repo/ossf/malicious-packages?utm_source=readme_badge) [![Global Rank](https://githubrepo.cloud/badge/ossf/malicious-packages.svg?metric=rank)](https://githubrepo.cloud/repo/ossf/malicious-packages?utm_source=readme_badge)

Momentum

+16

STARS · LAST 30 DAYS

1

PER DAY

#689

MOST-STARRED Go

Window7 days30 days90 days
Stars gained+7+16+90
Per day111
Forks gained+1+3+10

malicious-packages gained 16 stars in the last 30 days, about 1 a day, and now has 622. It is about 4 years old and has averaged roughly 156 stars a year. It ranks #689 among Go repositories and #6,311 across all languages on GitHubRepo.

Trending Record

malicious-packages has maintained a continuous presence across global trending indexes, peaking at #6432. Below is the 30-day activity profile:

💡 Overview

malicious-packages is an open-source project written in Go: A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.

Engineered for speed, consistency, and developer ease, it solves common hurdles in Go. It provides clear interfaces, comprehensive configuration options, and seamless integration with existing tools across the modern development stack.

⚡ Key Features

1

Optimized execution pipeline written in Go for predictable speed.

2

Zero-friction configuration with comprehensive sensible defaults out of the box.

3

Cross-platform runtime support across Linux, macOS, and Windows environments.

4

Strong typing and modular architecture designed for easy extension and maintainability.

5

Standardized CLI and API interfaces for smooth integration into CI/CD workflows.

6

Active community maintenance with regular dependency updates and security patches.

📥 Installation

terminal
$ go install github.com/ossf/malicious-packages@latest

⚙ System Requirements

Platforms

  • • macOS
  • • Linux
  • • Windows

Runtime & Dependencies

Go >= 1.21 runtime environment

Architecture

x86_64, ARM64 (Apple Silicon & Graviton)

🧠 How It Works

malicious-packages coordinates its core functionality through a modular Go pipeline. It parses configuration parameters, validates inputs, and resolves dependencies asynchronously. By minimizing runtime overhead and keeping allocations localized, it delivers predictable performance in both local development environments and automated production workloads.

🎯 Production Use Cases

Production System Integration

Embed malicious-packages into Go backend services to handle core application logic.

CI/CD Automated Pipelines

Run automated validation, builds, and integration suites during deployments.

Developer Tooling & Workflows

Accelerate developer onboarding with pre-configured project utilities.

Open Source Extension

Fork and customize internal modules under the repository's open Apache-2.0 license.

🚀 Getting Started

1

Install malicious-packages using your package manager: `go install github.com/ossf/malicious-packages@latest`

2

Initialize your project workspace or configuration file for malicious-packages.

3

Import malicious-packages into your codebase or invoke it directly from your terminal.

4

Execute your test suite or run `malicious-packages --help` to verify successful setup.

👍 Strengths

Active community backing with 622 GitHub stars and verified adoption.
Permissive open-source distribution under the Apache-2.0 license.
Built in Go for high execution speed and developer familiarity.
Cross-platform compatibility across modern Linux, macOS, and Windows environments.
Clean modular design allowing flexible configuration and pipeline integration.

⚠️ Considerations

Requires familiarity with Go and modern CLI workflows.
Ecosystem extensions may require manual configuration depending on environment constraints.
Active development roadmap means breaking API changes may occur across major versions.

⇄ Alternatives & Direct Competitors

A
avelino/awesome-go ★ 187.2K Go

A curated list of awesome Go frameworks, libraries and software

Compare ↗
O
ollama/ollama ★ 182.3K Go

Get up and running with Kimi, GLM, MiniMax, DeepSeek, gpt-oss, Qwen, Gemma and other models.

Compare ↗
G
golang/go ★ 139.1K Go

The Go programming language

Compare ↗
K
kubernetes/kubernetes ★ 128.2K Go

Production-Grade Container Scheduling and Management

Compare ↗

👥 Who Should Use This

Developers and engineering teams building with Go, seeking reliable, tested, and actively maintained tooling for production workloads.

🏆 Nearby in the Rankings

ossf/malicious-packages is currently ranked #6,311 by stars across every repository tracked on GitHubRepo. These are adjacent projects:

RankRepositoryLanguageStarsAction
#6,305 nahrek/polyledger Python ★ 623 Compare ↗
#6,305 dlsc-software-consulting-gmbh/GemsFX Java ★ 623 Compare ↗
#6,305 peej/tonic PHP ★ 623 Compare ↗
#6,305 ruby/spec Ruby ★ 623 Compare ↗
#6,305 pyenchant/pyenchant Python ★ 623 Compare ↗
#6,311 ossf/malicious-packages This Project Go ★ 622
#6,311 ChrisChen667788/wind-comic TypeScript ★ 622 Compare ↗
#6,311 BestImageViewer/geeqie C++ ★ 622 Compare ↗
#6,311 rspatial/terra C++ ★ 622 Compare ↗
#6,311 DataDog/orchestrion Go ★ 622 Compare ↗
#6,311 basecamp/activerecord-tenanted Ruby ★ 622 Compare ↗

Frequently Asked Questions

What does malicious-packages do? +

A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.

What language is malicious-packages written in? +

The primary language is Go. Topics include: software.

Is malicious-packages actively maintained? +

Yes, the last recorded push was on Oct 6, 2026 with 60 open issues being tracked.

How many stars does malicious-packages have? +

malicious-packages has 622 stars and 157 forks on GitHub.

How does malicious-packages rank among GitHub repositories? +

With 622 stars, ossf/malicious-packages is ranked #6,311 globally across all repositories tracked on GitHubRepo and #689 among Go projects.

What license is malicious-packages distributed under? +

The repository reports a Apache-2.0 license. Always verify the repository LICENSE file for legal terms.

From our network
FOR MAINTAINERS

Built something? Put it in front of millions of developers.

We make a short reel about your project and post it across YouTube, Instagram, Threads, and X. Send a link, we do the rest.