Skip to main content
All OpenSourceMalware threat records are tagged with various categories keywords that help you to better understand the threats and look for trends. For example, you can use tags to:
  • Quickly filter the web UI search by keyword - search for #tag-name on opensourcemalware.com
  • Pivot on a tag within a threat record (on the website) to see all records associated with that concept
  • If you’re consuming the APIs, use tags from the responses to internally filter reports and set up your own workflows (e.g. alerts)
When searching by tag on the homepage, use all lowercase and replace spaces with hyphens. For example: account-takeover or teampcp, not Account Takeover or TeamPCP.
This page is not an exhaustive list of tags used in the platform. As new malware and campaigns are discovered, naturally new tags are needed.

Tag categories

Our tags generally fit into these 11 categories:

Ecosystem

Although the threat records are categorized by ecosystem, we also add an ecosystem tag to offer faster searches.

Attribution

Attribution tags require high-confidence evidence. We break attribution into three categories:
  • Threat actor group
  • Campaign
  • Malware family
A record can carry attribution tag types independently. For example, a confirmed malware family doesn’t require a known campaign, and a known campaign doesn’t require an identified threat actor group.

Threat actor group

Threat actor group is the most challenging attribution category because most threat actors don’t want to be recognized. Two that you will see frequently used in our records are:

Campaign

Campaign tags identify a named, tracked series of related attacks. These are some examples:
  • glassworm is an unattributed campaign first discovered in October 2025. It targets software developers by compromising popular extensions (such as for VS Code or OpenVSX) and packages across ecosystems like npm, PyPI, and GitHub.
  • contagious-interview (fake interviews aimed at infecting developers with malware for the purpose of stealing crypto and credentials) and polinrider (a persistence and infection mechanism often packaged up in the Contagious Interview malware) are two related campaigns attributed to North Korean state actors.
  • shai-hulud was an unattributed npm worm campaign during 2025. mini-shai-hulud was an unrelated npm worm disseminated by TeamPCP in 2026.
  • indonesianfoods was a npm spam campaign that doubled the volume of malicious npm findings in 2025.
  • agentbaiting is an ongoing campaign where the threat actor spreads lure repos on GitHub to trick agents into installing malware.
Where a campaign has sub-variants or waves, we may use an umbrella tag (such as shai-hulud) and a specific variant tag (e.g. shai-hulud-second-coming).

Malware family

Malware families are strains of malware that are reused by threat actors across multiple attacks or through an extended campaign. These are just some of the ones we have tagged:

Malware type

This category describes what the malware does and may include several complementary tags. For example, a malicious package can be both a dropper and an infostealer.
trojan and trojanized are distinct. trojan describes a package built from scratch to appear legitimate. trojanized describes a package that was once legitimate and has been modified by an attacker.

Attacker tactic

How the attacker delivered or disguised the malware.
account-takeover signals that a previously trusted package has been weaponized. When you see this tag, the package was once safe. Prioritize review of any use of this package prior to the compromise date.

Name confusion sub-types

When applying name-confusion, also apply the appropriate sub-type tag.

Execution method

How the malware runs. These tags describe the mechanism of execution, not the payload behavior.

Infrastructure

Services, platforms, or protocols abused as part of the attack operation. May be used for exfiltration, C2, or payload hosting.

Targeting

What the malware is specifically going after. This is just an example list - there are many other targets.

Victim

A specific organization, platform, or technology targeted by the attack. The actual brand may be the target, or users of the brand’s services. We typically use this when the record is part of a campaign directed at a named target. For example: aws, mastra, anthropic, openai, okta, coinbase, redhat.
Some tags like aws can appear in both Targeting and Victim depending on context.

Language

The human language present in the malware or package content. Useful for attribution and clustering. For example: