- Quickly filter the web UI search by keyword - search for
#tag-nameon opensourcemalware.com - Pivot on a tag within a threat record (on the website) to see all records associated with that concept
- If you’re consuming the APIs, use tags from the responses to internally filter reports and set up your own workflows (e.g. alerts)
Tag categories
Our tags generally fit into these 11 categories:Ecosystem
Although the threat records are categorized by ecosystem, we also add an ecosystem tag to offer faster searches.Attribution
Attribution tags require high-confidence evidence. We break attribution into three categories:- Threat actor group
- Campaign
- Malware family
Threat actor group
Threat actor group is the most challenging attribution category because most threat actors don’t want to be recognized. Two that you will see frequently used in our records are:Campaign
Campaign tags identify a named, tracked series of related attacks. These are some examples:glasswormis an unattributed campaign first discovered in October 2025. It targets software developers by compromising popular extensions (such as for VS Code or OpenVSX) and packages across ecosystems like npm, PyPI, and GitHub.contagious-interview(fake interviews aimed at infecting developers with malware for the purpose of stealing crypto and credentials) andpolinrider(a persistence and infection mechanism often packaged up in the Contagious Interview malware) are two related campaigns attributed to North Korean state actors.shai-huludwas an unattributed npm worm campaign during 2025.mini-shai-huludwas an unrelated npm worm disseminated by TeamPCP in 2026.indonesianfoodswas a npm spam campaign that doubled the volume of malicious npm findings in 2025.agentbaitingis an ongoing campaign where the threat actor spreads lure repos on GitHub to trick agents into installing malware.
shai-hulud) and a specific variant tag (e.g. shai-hulud-second-coming).
Malware family
Malware families are strains of malware that are reused by threat actors across multiple attacks or through an extended campaign. These are just some of the ones we have tagged:Malware type
This category describes what the malware does and may include several complementary tags. For example, a malicious package can be both adropper and an infostealer.
trojan and trojanized are distinct. trojan describes a package built from scratch to appear legitimate. trojanized describes a package that was once legitimate and has been modified by an attacker.Attacker tactic
How the attacker delivered or disguised the malware.Name confusion sub-types
When applyingname-confusion, also apply the appropriate sub-type tag.
Execution method
How the malware runs. These tags describe the mechanism of execution, not the payload behavior.Infrastructure
Services, platforms, or protocols abused as part of the attack operation. May be used for exfiltration, C2, or payload hosting.Targeting
What the malware is specifically going after. This is just an example list - there are many other targets.Victim
A specific organization, platform, or technology targeted by the attack. The actual brand may be the target, or users of the brand’s services. We typically use this when the record is part of a campaign directed at a named target. For example:aws, mastra, anthropic, openai, okta, coinbase, redhat.
Some tags like
aws can appear in both Targeting and Victim depending on context.
