← back

ProfMalPlus: Agent-Coordinated Detection of Malicious NPM Packages via Static-Dy

Open source software is vulnerable to supply-chain attacks through transitive dependencies, especially malicious code injected into NPM packages. Existing detectors often inadequately model obfuscated behavior, overlook JavaScript's object-

https://arxiv.org/abs/2607.13965v1 ↗
Thesis fit
Good fit

Within your typical scope; diligence still required.

Edit thesis
In your usual scope
Idea match Light

How close the company’s idea is to your thesis statement

Sector ai

Overlap with sectors you care about

Geography Unknown

Location unknown — scores 0

Your thesis: “We back exceptional technical founders building AI-first products and infrastructure, deploying $100K checks within 24 hours.”

Founder → stable Traction → stable Idea vs market ↓ declining
Generate memo
Add / edit details

Correct facts used on the next screening or memo.

Similar baseline plays (YC · idea space)

LunaSec · Inactive
An Open Source dependency security tool that is smarter than the rest
founders not scraped yet
ZeroPath · Active
Automatically find and fix your software vulnerabilities
founders not scraped yet
OpenProse · Active
An open-source operating system for reliable long-running agents
founders not scraped yet
OpenFoundry · Active
The fastest developer experience for building on open source AI.
founders not scraped yet
Federacy · Active
Penetration testing and bug bounty platform.
founders not scraped yet