ProfMalPlus: Agent-Coordinated Detection of Malicious NPM Packages via Static-Dy
Open source software is vulnerable to supply-chain attacks through transitive dependencies, especially malicious code injected into NPM packages. Existing detectors often inadequately model obfuscated behavior, overlook JavaScript's object-
https://arxiv.org/abs/2607.13965v1 ↗Thesis fit
Good fit
Within your typical scope; diligence still required.
In your usual scope
Idea match
Light
How close the company’s idea is to your thesis statement
Sector
ai
Overlap with sectors you care about
Geography
Unknown
Location unknown — scores 0
Your thesis: “We back exceptional technical founders building AI-first products and infrastructure, deploying $100K checks within 24 hours.”
Founder → stable
Traction → stable
Idea vs market ↓ declining
▸ Add / edit details
Correct facts used on the next screening or memo.
People
Y
Yiheng Huang
1.0
low confidence
Z
Zhijia Zhao
1.0
low confidence
B
Bihuan Chen
1.0
low confidence
S
Susheng Wu
1.0
low confidence
Z
Zhuotong Zhou
1.0
low confidence
Y
Yiheng Cao
1.0
low confidence
X
Xin Hu
1.0
low confidence
X
Xin Peng
1.0
low confidence
Activity & evidence
Similar baseline plays (YC · idea space)
LunaSec
· Inactive
An Open Source dependency security tool that is smarter than the rest
founders not scraped yet
OpenProse
· Active
An open-source operating system for reliable long-running agents
founders not scraped yet
OpenFoundry
· Active
The fastest developer experience for building on open source AI.
founders not scraped yet