Malicious package detection
Detect and avoid malware
Fortify SCA identifies malicious packages in your dependencies and separates them from standard security vulnerabilities. This helps you triage intentional compromise faster and prioritize response actions across repositories.
Fortify SCA uses malware intelligence sources, including OSV, to detect known malicious packages. Finding details can include advisory references and dependency context.
See repositories with malware findings
To get an overview of repositories with malware findings, click Repositories in the left side menu.

In this view, Fortify SCA displays:
Name: Repository name.
Malware detected banner: Indicates when malware findings exist in the selected repository context.
Malware finding count: Total malware findings detected in the repository.
Malware Detected column: Malware indicator for repository or dependency rows.
Review status: Current review state for findings in the repository.
You can export the filtered and visible repository data in the table to a CSV file. To do so, click Export Table located at the top-right corner of the table. For more information, refer to the Export table data topic.
See malware findings in a specific repository
To show all malware findings in a specific repository:
Go to Repositories from the left side menu.
Click a specific repository.
In the repository view, click the Malware tab.

In this view, you get detailed information regarding malware findings discovered in your repository:
Name: Malware identifier, typically a MAL ID.
Discovered: Date when Fortify SCA detects the finding in the repository.
Dependencies: Dependency in which Fortify SCA detects the malicious package.
Review status: Indicates whether the finding is marked as vulnerable, unaffected, paused/snoozed, or unexamined.
For more information on review states, refer to the Set a review status topic.
See information about a specific malware finding
To get detailed information about a specific malware finding in a repository, click the malware ID.
This view contains links to advisories and malware intelligence references, along with a summary of impact.
The summary contains the following information:
Affected dependency and version details.
Discovery metadata for the finding.
External references related to malware analysis and remediation.
Classification metadata, including CWE where available (for example, CWE-506).
See all malware findings across all projects
To get an overview of all malware findings across scanned repositories:
Click Vulnerabilities in the left side menu.
Click the Malware tab.

This view is similar to the malware view for a specific repository, but it includes all malware findings across all projects.
You can export the filtered and visible vulnerability data in the table to a CSV file. To do so, click Export Table located at the top-right corner of the table. For more information, refer to the Export table data topic.
See dependencies affected by malware
To view impacted dependencies in repository context:
Go to Repositories.
Click a specific repository.
Click the Dependencies tab.
Review the Malware Detected column.

Use this view to connect malware findings directly to affected packages and prioritize remediation work.
See malware entries in Vulnerability Database
To review malware intelligence entries:
Open Vulnerability Database.
Click the Malware tab.
Search by malware ID or dependency.
Sort by Published to review the newest entries first.

This view helps you validate malware context and supports investigation.
Use automation to respond to malware findings
The automation engine helps you reduce manual response work by reacting immediately to malware findings.
You can configure automation rules to:
Trigger notifications when Fortify SCA detects malware.
Trigger webhooks for incident workflows.
Fail pipeline checks when malware is present in a repository.
For more information, refer to the Automation and Policies topics.
Data sources for malicious package detection
Fortify SCA continuously collects and refines malware intelligence data to identify malicious packages and map findings to dependencies.
For more information on source processing and enrichment, refer to the Data sources topic.
Last updated
Was this helpful?

