Malicious Packages Identification API (MPIAPI)
Free Virtual Summit Agentic AppSec Unleashed '26 is June 16th Register Now
Outlook Report The Future of Application Security in the Era of AI Download Now
Checkmarx for Developers
Blog
Research
Software Supply Chain Security

Malicious Packages Identification API
(MPIAPI)

Easily integrate malicious package detection across the entire SDLC to prevent
the threats of malicious open-source libraries.

The Threat

Why Malicious Package Defense Is Critical

The dramatic rise in open-source malicious packages is increasing the frequency and severity of software supply chain attacks.

92%

Increase in identified malicious packages from 2022 to 2024

76%

Of CISOs are concerned about the dangers of malicious packages

68%

Increase in supply-chain-related breaches between 2023 and 2024

93%

Of companies have experienced a supply chain attack

How It Works

Protect your Organization from the Dangers of Malicious Packages

Malicious packages pose a unique AppSec risk because they can compromise your systems merely by being installed. MPIAPI provides a unique solution to this critical defense challenge.

SDLC Coverage

Available at Every Stage of the SDLC

Incorporate MPIAPI calls at key stages to block malicious packages — for example, before downloads, during CI/CD workflows, or before adding packages to a private artifact registry.

Available at Every Stage of the SDLC
Threat Database

The Largest Malicious Packages Database

With over 420K human-verified malicious packages across 92.8M versions (and counting), Checkmarx leads the industry with the most comprehensive malicious package repository.

The Largest Malicious Packages Database
Risk Intelligence

Detailed Package Risk Information

Query responses provide package details, a 1–10 risk score (10 = certain malicious), and IoCs such as suspicious files, domains, or IP addresses.

Detailed Package Risk Information
Reduce Risk

Maximize Your Software
Supply Chain Defenses

Learn how leading enterprises use MPIAPI to reduce the risks of malicious packages in their software supply chains.

Why MPIAPI

Protect your Organization from
Malicious Package Threats

Reduce OSS security threats and improve your overall security posture by blocking malicious or suspicious third-party packages that can put your organization at risk.

Unmatched OSS Risk Visibility

Reduce OSS security threats and strengthen your security posture by blocking malicious or suspicious third-party packages that could put your organization at risk.

Protection Across Your Entire Environment

Leverage the industry’s largest malicious package database, with over 420,000 packages spanning multiple OSS ecosystems, including PyPI, npm, RubyGems, NuGet, and Maven Central.

Turbo-Charged AppSec Research

Rapidly assess third-party packages with detailed intelligence to set security policies, evaluate suspicious components, and balance risk with developer productivity.

Technology Agnostic Solution

No matter which tech stack your org is using you can still utilize the MPIAPI.

Common Questions

Frequently Asked Questions

Discover Checkmarx’ Malicious Package Protection

See how easy it is to ensure that malicious and suspicious OSS packages do not put your business at risk.

Thank You!

Your Custom Checkmarx Demo Request
was Successfully Sent!

thank you page decoration

Get a Demo

Stop Malicious Packages Before They Compromise Your Build

Stop supply‑chain malware early

Detect malicious & suspicious OSS across ecosystems with the industry’s largest database (420k+), not just CVE‑tracked vulns.

Detect across the SDLC

Manifests, binaries, containers – plus runtime correlation to prioritize what’s actually in use.

Automate policy actions

Block builds and enforce guardrails to reduce mean‑time‑to‑contain.

Developer‑first prevention

Surface malicious‑package alerts directly in the IDE via Developer Assist to fix before commit.

One platform view

Fold MPP into Checkmarx One for unified reporting across SAST, SCA, IaC, Secrets.

Get a Demo

Learn More
About the MPIAPI

Learn how your enterprise can implement calls to this API to prevent malicious packages from entering your environment and causing damage.

Gartner Magic Quadrant Leader
Forrester Wave Leader
SOC 2 Type II Certified