Phylum provides a software supply chain security solution that utilizes static application security testing (SAST), heuristics, and machine learning to identify and block malicious open-source packages before installation. By analyzing software packages for risks such as vulnerabilities and malware, Phylum helps organizations mitigate threats to their development lifecycle and maintain compliance with security policies.
Funding
$15M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.


CFounders
Product
Problem
Organizations face increasing risks from malicious code, vulnerabilities, and supply chain attacks embedded in open-source software packages. Existing security solutions often rely on curated lists and struggle to identify zero-day threats early in the development lifecycle. This leaves development pipelines vulnerable to compromised packages that can exfiltrate data, inject malware, or create backdoors.
Solution
Phylum provides a software supply chain security platform that proactively identifies and blocks malicious open-source packages before they are installed. The platform employs static application security testing (SAST), heuristics, and machine learning to analyze packages for a broad range of risks, including malware, vulnerabilities, engineering risks, and license issues. Phylum's automated analysis engine reports proprietary findings, providing users with early warnings of zero-day threats that are not found on curated lists. Organizations can define flexible policies to map risks to their specific threat models and enforce governance across their software supply chain.
Target Audience
Phylum is designed for development, security, and operations teams that need to secure their software supply chain and mitigate risks associated with open-source software.
Features
- Automated analysis of open-source packages using SAST, heuristics, and machine learning
- Detection of malicious code, author reputation risks, engineering risks, abandoned packages, license issues, and software vulnerabilities
- Proprietary analysis engine that identifies zero-day findings not available on curated lists
- Flexible policy engine for mapping risks to specific threat models and compliance requirements
- Integration with CI/CD pipelines to block malicious packages before installation
- Comprehensive software value chain view for identifying and mitigating supply chain risks
- Command-line interface (CLI) for direct access to the Phylum platform
- Cross-platform execution sandbox for package installation analysis