Phylum

Software supply chain risk analysis with ML-based malicious package detection

About Phylum

Phylum uses static analysis, heuristics, and machine learning to detect malicious open-source packages in real time, including zero-day supply chain attacks. It can be deployed in front of artifact repositories like Artifactory and Nexus to block dangerous packages before they enter a codebase. Phylum was acquired by Veracode in 2025 and now powers Veracode's software composition analysis.