Apiiro unveils free scanner to detect malicious code merges
Security researchers at Apiiro have released two free, open-source tools designed to detect and block malicious code before they are added to software projects to curb supply chain attacks.
The two tools consist of a comprehensive ruleset for Semgrep and Opengrep designed to detect malicious code patterns with minimal false positives and PRevent, a GitHub-integrated scanner, that detects and alerts on suspicious code in pull requests (PRs).
According to Apiiro's security researcher Matan Giladi, the tools have a minimal false positive detection rate, making them particularly valuable in real-world practice.
Specifically, the detection accuracy of the ruleset for PyPI packages is 94.3%, while it drops to the still impressive 88.4% for npm packages. PRevent successfully flags malicious PRs in 91.5% of the examined cases.
data:image/s3,"s3://crabby-images/931b4/931b4c47d69f882808deff53a5d0b7cf5498f56c" alt="Detection test results"
Catching malicious code
Apiiro's malicious code detection strategy is based on identifying "code anti-patterns," which are suspicious patterns in code that demonstrate behaviors that are rare in legitimate code but common in malware.
The detection system uses static analysis, meaning it examines code without executing it, keeping the environment safe from accidental infections.
These anti-patterns include:
- Various obfuscation methods like encoding, nested transformations, and runtime modifications that help hide the code's functionality and intent.
- Use of exec(), eval(), or similar functions, which allow arbitrary code execution at runtime.
- Code that downloads and executes remote payloads from external, unknown servers.
- Methods for exfiltrating sensitive user data to external locations.
This ruleset can be integrated into CI/CD pipelines for automatic repository scanning, used for scanning npm and PyPI packages, or adapted to other platforms using Semgrep or Opengrep.
PRevent, which uses the same anti-patterns, is designed to scan pull request events in real-time before code is merged, stopping any threats before they reach production.
data:image/s3,"s3://crabby-images/d7577/d75771dcfa8ff456764554bcbaec983f7adcd86e" alt="PRevent warns about malicious code in the PR"
It can be set to block the merging until an authorized reviewer approves it or add comments on detected issues to ensure developers are alerted of the risks.
data:image/s3,"s3://crabby-images/ae494/ae494a03e994b237d5e16aeb4636d6489e937841" alt="Issue prompting review"
Apiiro acknowledges that its tools are still practically limited, as they cannot detect malware hidden in compiled binaries nor scan npm and PyPI packages directly, but plans to add more features like deep code analysis and AI-assisted scans in future updates.
Both the malicious code detection ruleset and the PRevent tool are available for free on GitHub, with instructions on how to use them.
BleepingComputer has not tested these security tools and cannot guarantee their effectiveness or safety.
source: BleepingComputer
Free online web security scanner
Top News:
data:image/s3,"s3://crabby-images/2729a/2729a75cd8e4c2ac074c8f7b1a235ff5c201c2de" alt="Content Credentials Technology Verifies Image, Video Authenticity"
Content Credentials Technology Verifies Image, Video Authenticity
February 13, 2025data:image/s3,"s3://crabby-images/2a8f2/2a8f25f2771a735a5732b219744bac98ac65890d" alt="New NailaoLocker ransomware used against EU healthcare orgs"
New NailaoLocker ransomware used against EU healthcare orgs
February 20, 2025data:image/s3,"s3://crabby-images/af307/af3075d52e0996a9367de185e5d61972364357d9" alt="Windows Server 2025 released—here are the new features"
Windows Server 2025 released—here are the new features
November 5, 2024data:image/s3,"s3://crabby-images/6bfe1/6bfe17e13ec14d5acd25ce17406f0aef0fa64412" alt="Chinese hackers abuse Microsoft APP-v tool to evade antivirus"
Chinese hackers abuse Microsoft APP-v tool to evade antivirus
February 19, 2025data:image/s3,"s3://crabby-images/3017e/3017e751ec93262afe4df49f5b0da11d53687dbd" alt="Microsoft: Hackers steal emails in device code phishing attacks"
Microsoft: Hackers steal emails in device code phishing attacks
February 15, 2025data:image/s3,"s3://crabby-images/9fe69/9fe697d996e75f4f08479a7105568a822cb90af0" alt="PirateFi game on Steam caught installing password-stealing malware"
PirateFi game on Steam caught installing password-stealing malware
February 15, 2025