Top threat intelligence feeds in 2026
"Threat intelligence feed" spans everything from network IOC blocklists to dark web tracking. Increasingly, it means open source package intelligence, the segment this post covers.
Supply chain attacks landed almost weekly in 2026, including August's compromise of keyv, a caching library with roughly 127 million weekly downloads. CVE-matching tools won't catch this. Malware rarely gets a CVE, since CVEs are meant for vulnerabilities in legit software. Malicious packages are usually pulled within hours, before any public database catches up anyway. Those databases are struggling too, and since April 2026 the National Vulnerability Database only fully analyzes the most critical CVEs.
In Q2 2026, Aikido Intel confirmed 19,500 malicious packages. Without a publicly provided option, companies and organizations have stepped in to fill the void with the goal of keeping up with malware as it appears. The feeds below differ most on how early they catch a threat and whether they can stop it at install.
In this post, we compare:
- Aikido Intel: Best for early warning on malicious packages and undisclosed vulnerabilities across 20 ecosystems
- Socket Threat Feed: Best for teams focused on package behavior at the PR and install layer
- Snyk Security Database: Best for teams already standardized on Snyk who want vulnerability intelligence inside their existing scanners
- OSV.dev: Best as a free reference for disclosed vulnerabilities and reported malware
- Spectra Intelligence (ReversingLabs): Best for regulated teams that need forensic depth on binaries and artifacts
{{cta}}
Which threat intelligence feeds should you shortlist?
If you need early warning on malicious open source packages
- Aikido Intel: Analyzes and tracks both malware and undisclosed vulnerabilities across many ecosystems and publishes an open feed, including package behavioral analysis
- Socket Threat Feed: Behavioral analysis of what a package does
If you want open source vulnerability intelligence for your dev and AppSec workflow
- Aikido Intel: Surfaces pre-CVE and undisclosed vulnerabilities alongside malware in one feed, available through an API and Safe Chain's install-time blocking
- Snyk Security Database: Offers a mature advisory database tightly bound to its platform
If you want a zero-cost feed to start with, machine-consumable
- Aikido Intel: Open source supply chain threat intelligence feed
- OSV.dev: Aggregates known OSS vulnerabilities for free but is CVE-based and detection comes after disclosure
If you need to vet binaries and third-party artifacts
- Spectra Intelligence (ReversingLabs): File reputation and malware analysis drawn from a large sample corpus, useful for binaries and vendor software
Where threat intelligence feeds often fall short
- Most feeds rely on CVE data, so a vulnerable package only gets flagged once it's been disclosed and assigned an ID. By then, the malicious version has been live for hours or days.
- The public data underneath many feeds is thinning out: Since April 2026, NIST no longer fully enriches most CVEs in the NVD, so any feed that mirrors it inherits entries with no severity score and no affected-version data. A feed is only as good as the source it reads, and the main public sources are no longer keeping up with the volume.
- Malware and vulnerabilities are separate problems, and plenty of feeds only handle one well. A vulnerability scanner that looks for flaws in legitimate code won't flag a package that was compromised and is now trying to steal your npm token.
- Coverage tends to stop at the main package registries, so GitHub Actions and extension marketplaces get left out even though attackers actively ship malware to both.
- Alert-only feeds tell you something's wrong after the package is already in your build. With no enforcement at install time, the finding shows up too late to do anything about it.
- Intelligence is often locked inside the vendor's own platform, so you can't pipe it into the tooling or AI agents you already run.
Top threat intelligence feeds
Aikido Intel
What it does: Aikido Intel is a real-time, open feed that tracks malware and undisclosed vulnerabilities across more than four million open source packages in 20 ecosystems. These include npm, PyPI, Maven, and Go, as well as GitHub Actions, VS Code and browser extension marketplaces, and WordPress plugins.
Why it stands out: Aikido Intel analyzes what package code does. New packages are deobfuscated and checked against Opengrep and YARA-X rules. npm packages are also detonated in a sandbox. AI traces behavior across files, and anything it can't rule out as safe goes to Aikido's security researchers, who make the final call by hand. That team writes the detection rules and watches the pipeline around the clock from three continents. Intel caught s1ngularity/nx and both Shai-Hulud waves early, and during the second wave, lead security researcher Charlie Eriksen published the list of 400+ infected npm packages that other research teams used to corroborate their own findings. The team's work is regularly cited by KrebsOnSecurity. Packagist blocks Composer downloads the feed flags. Latio's 2026 AppSec report singled out its pre-disclosure vulnerability work.
For vulnerabilities, Intel reads changelogs on open source packages to catch security fixes that maintainers ship silently, and publishes them with Aikido IDs even when no CVE follows. Besides enriching vulnerabilities, Intel sends the relevant findings to the patch-building pipeline to power Aikido Libraries. Aikido customers receive the fix as a patched, compatible variant of the same package version, without even having to check the vulnerability feed themselves. Each undisclosed vulnerability is reviewed and validated by one of Aikido's security engineers before it's published with an Aikido Vulnerability ID and severity score.
Intel also powers Safe Chain, which does free install-time blocking, and Device Protection, which enforces that blocking on developer machines and extends it to IDE and browser extensions.
What to know: Browsing and search are free at intel.aikido.dev, and teams that want to build on the data can license the full database through the commercial API. Coverage is limited to the open source supply chain, so the feed doesn't include network indicators of compromise (IOCs) or adversary attribution.
Socket Threat Feed
What it does: A commercial feed of malicious and suspicious packages, detected by Socket's scanning of open source registries such as npm, PyPI, Maven, and Go.
Why it stands out: Socket analyzes what package code does. It flags install scripts, network calls, filesystem access, obfuscation, and shell execution. That behavioral approach catches typosquats and hijacked maintainer accounts before they get CVEs. Findings also flow into Socket's GitHub app, CLI, and dependency firewall.
What to know: The feed sits on Socket's enterprise tier, so most smaller teams meet it through the product and never touch the raw API. It focuses on malicious behavior, which leaves undisclosed vulnerabilities in legitimate packages with less coverage. Socket's AI flags a package as soon as its behavioral signals trip, and human review happens after that label is public. The ordering gets alerts out fast, but it also means legitimate packages sometimes get flagged, and their maintainers have to dispute the label before it's cleared.
Snyk Security Database
What it does: Snyk's curated vulnerability database covers open source packages across major ecosystems, plus container base images. The public can browse it at security.snyk.io.
Why it stands out: Snyk's research team adds advisories beyond the NVD, including issues from its own research. Each entry is enriched with severity, exploit maturity, and fix guidance such as the minimum safe version. That context drives Snyk's prioritization and automated upgrade pull requests.
What to know: The database exists to feed Snyk's platform, and programmatic access generally comes with a Snyk license rather than as a standalone feed. It's vulnerability-focused, so its malicious package coverage is narrower than dedicated malware feeds. Teams not running Snyk get limited value beyond the public site.
OSV.dev
What it does: A free, Google-run vulnerability database and API. It aggregates advisories from GitHub Security Advisories, PyPA, RustSec, Go, and many Linux distributions into the open OSV schema.
Why it stands out: The schema maps vulnerabilities to exact package versions and commit ranges, which cuts false positives compared with CPE-based matching. It's easy to query in CI and pairs with the open source OSV-Scanner. It also includes malicious package reports from the OpenSSF Malicious Packages project.
What to know: OSV is an aggregator, so it only knows what upstream sources publish, and its coverage and timing depend on disclosure. It has no in-house research team, no fix guidance, and no SLA. It's a strong free baseline to layer other feeds on, not an early-warning source.
Spectra Intelligence (ReversingLabs)
What it does: ReversingLabs' commercial threat intelligence service. It provides file reputation, malware classification, and indicator data from a corpus of tens of billions of analyzed files, delivered through APIs and feeds.
Why it stands out: Its static analysis unpacks binaries, installers, archives, and documents to classify threats without executing them. That gives verdicts on artifacts that package-level feeds never see. SOC teams use it to enrich SIEM, SOAR, and TIP workflows with file hashes, network indicators, and threat names.
What to know: It's built for SOC and malware analysis teams rather than developer workflows, and pricing is enterprise-only. ReversingLabs packages its software supply chain analysis separately, in Spectra Assure. Expect integration work to get value beyond hash lookups.
How to choose a threat intelligence feed
- Decide what you need covered: Malware feeds catch packages built to attack you. Vulnerability feeds catch flaws in legitimate code. Some feeds do one, some do both, and most teams need both.
- Decide whether you need pre-disclosure signals: A database of known issues only tells you about vulnerabilities after someone reports them. Many maintainers fix security issues without disclosing them. If you want to know about those, you need a feed that reads code changes, not one that waits for CVEs.
- Check ecosystem coverage beyond package registries: npm and PyPI get the most attention, but attackers also target IDE extensions, browser extensions, and GitHub Actions. A feed that stops at registries misses live attack surfaces.
- Weigh free against commercial: Free feeds are enough for reference lookups and a baseline. Commercial access matters when you need programmatic use at scale, SLAs, or data piped into your own tooling. Decide whether you need an API or just a searchable feed.
- Factor in speed and false-positive rate: Supply chain attacks move in hours, so detection time is the core metric. A fast feed that floods your team with false positives just gets ignored, so check how findings are validated.
- Check how enforcement is applied: Some tools protect only the installs that run through a wrapper or a specific command. Developers can skip the wrapper, run a different package manager, or install from a machine where it isn't configured. Enforcement on the device itself covers every install regardless of how it runs.
- Check whether the feed helps you fix what it finds: A finding still leaves someone to upgrade the package and chase transitive dependencies. Some tools stop at the alert, while others hand you the fix. Aikido Libraries, for example, backports security patches into the version you've pinned and ships a clean lockfile as a merge request, including for end-of-life dependencies that can't be upgraded.
Conclusion
Open source threat intelligence feeds track malicious and vulnerable packages as they're published, giving teams a way to flag or block risky dependencies. For that job, Aikido Intel is the strongest early warning system on this list:
- It's frequently among the first to catch a supply chain attack, typically within minutes of a malicious version going live.
- It tracks malware and pre-CVE vulnerabilities in one feed.
- The full database is available to license through a commercial API.
- It powers Safe Chain for free install-time blocking and Device Protection for enforcement on every developer machine.
- It powers Aikido Libraries, so packages with discovered vulnerabilities get patched versions in a day. Pin & Protect makes sure your infrastructure always has the most up-to-date patches in the package version you like to use.
{{walkthrough}}
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.