AI-powered detector combining static & dynamic analysis to identify malicious NPM packages. Uses behavior sequence mapping and ML classifiers for high-accuracy detection of obfuscated attacks in the open-source ecosystem.
DONAPI is an AI-powered malicious NPM package detector that combines static and dynamic analysis to identify obfuscated attacks in the open-source ecosystem. The system uses behavior sequence knowledge mapping and machine learning classifiers to detect and categorize malicious packages into five types of attacks, including data theft, file manipulation, and reverse shells. This tool is designed for developers, security researchers, and organizations who need to protect their Node.js projects from malicious dependencies in the npm registry.
How the donated funds are distributed
Kivach works on the Obyte network, and therefore you can track all donations.